Phishing attacks have changed.
They’re no longer badly written emails you can spot a mile off. Recent phishing attacks are well researched, highly convincing, and often look exactly like messages you’d expect to receive – from suppliers, Microsoft, or even colleagues.
At Cipher, we see phishing every day. It remains the number one way cyber criminals gain access to businesses, regardless of size or industry.
A simple approach: If something arrives unexpectedly, don’t assume it’s safe.
Why Phishing is so Effective Now
Modern phishing works so well because it blends in.
Attackers now:
- Use real company names, branding and email signatures
- Reference genuine invoices, deliveries or ongoing projects
- Impersonate directors, finance teams and trusted suppliers
- Create urgency to push people into acting quickly
Even the most experienced users can get caught out – especially during busy periods.
Human awareness is paramount. Technology helps, but no security system blocks 100% of phishing attempts.
The Red Flags People Miss
Be cautious if a message:
- Applies pressure or urgency
- Asks you to sign in or act “immediately”
- Requests passwords, payments or MFA codes
- Contains links to websites you don’t normally use
- Looks right at first glance, but something feels off
A Simple Phishing Safety Checklist
Always check the full sender email address, not just the display name, and always take a close look at links – attackers use tiny visual tricks, such as using r + n (rn) which looks like an ‘m’ in the web address and is easy to misread. Your business systems are also typically logged in automatically, so if you are being prompted to login, it could be an attack.
Before you click, reply, or sign in:
- Stop and think – urgency is often the warning sign
- Assume unexpected emails could be malicious
- Never reply to a suspicious message to “check” it
- Verify independently using a known phone number or contact method
- Don’t enter business login details into unfamiliar portals
- Never share passwords or MFA codes
- When unsure, pause and check with your manager or IT provider before entering any login details
- If you do click on a link, you should never enter your username or password – go directly to the website yourself.
A few seconds of caution can prevent serious disruption to your business.
One Last Thing to Remember
Phishing doesn’t succeed because people are careless, it succeeds because attacks are convincing.
Our approach to cyber security isn’t about stoking fear. It’s about awareness, consistency, and knowing when to stop and check.
If you’d like a clear, honest conversation about how exposed your business may be to phishing, let’s talk. Book a no obligation chat for practical, jargon‑free advice and a straightforward view of your next steps.