Phishing is one of the oldest cyber scams. Yet it’s still one of the cheapest and most effective, costing as little as £40 to carry out a profitable criminal campaign. Today, phishing remains the most common initial attack vector, and it is likely to become even more of a threat in the future as AI levels up cybercriminals’ capabilities whilst reducing phishing’s cost and complexity.
In the United Kingdom, the total cost of fraud doubled to £2.3 billion in 2023, according to BDO. A rise in the number of phishing attacks has contributed to this alarming increase. Earlier in 2024, the British government warned that phishing is “by far the most common type of cybercrime,” reporting that 84% of businesses have suffered attacks involving fraudulent emails or websites.
In an era when fraud is bad and getting worse, organisations have no choice but to improve their security postures, become more aware of phishing attacks, and prepare to defend themselves against increasingly sophisticated cyberattacks.
What is phishing, and why is it a threat?
Phishers are con artists who operate in the same digital spaces as your colleagues. In 2023, Barclays warned that 77% of scams today occur on social media, e-commerce, and dating apps.
Traditionally, phishers used bogus emails to distribute malware or steal credentials, financial data, and personally identifiable information. They now deploy text messages, phone calls, and social media posts but aim to exploit every possible medium.
Scammers have impersonated organisations such as Currys and the BBC as well as prominent celebrities. Consumer finance expert Martin Lewis said he felt “sick” after seeing an AI-generated deepfake video in which his digital likeness asked viewers to give money to what was claimed to be an Elon Musk-backed investment scheme.
One scam tactic involves posing as a representative of UPS, Evri, or the Post Office in texts about supposed missed deliveries. Bogus tax refund offers are also common; His Majesty’s Revenue and Customs warned that 207,800 were sent via text and email in just one year, spiking ahead of the tax return deadline in January 2024.
Recommended reading
- Scots Researchers Help Build AI Model for Identifying Pre-eclampsia Risks
- Can AI Help Radiologists With Breast Cancer Screening?
- Persistent Data Breaches Are Failing People With HIV
Novel attacks and the evolution of phishing
Phishing campaigns are becoming more innovative as scammers devise increasingly novel tactics, such as embedding malicious QR codes in phishing emails. The infamous CL0P Ransomware Gang used malicious redirect hyperlinks to deliver new variants of Truebot malware.
There has also been an increase in Qbot Trojan attacks, with new variants discovered in January 2024. These attacks involve emails with context-aware information, such as invoices, shipping details, and urgent requests, that contain a link or attachment from a supposedly trusted source. Many are sent as reply-chain emails to add credibility. If just one person clicks a malicious attachment, it can trigger a malware download, and the system or network will be hacked.
The unsubscribe malware scam is another new phishing tactic that shows the growing sophistication of scams. It invites a victim to press the unsubscribe button in a fraudulent email, which shows scammers that the victim’s email address is active, so they can be targeted with more phishing emails or led to a website rigged to trigger malware downloads. It is worth noting that the best way to deal with unsolicited emails is to mark them as spam, delete them, or block the senders without interacting with their emails.
Domain impersonation and business email compromise attacks have also spiked. A small tweak to an organisation’s familiar domain or the display name of a current employee can easily trick people into thinking a malicious request is legitimate.
These are just some of the many threats facing organisations. Unfortunately, more are on the horizon as phishers refine their AI skills and the technology matures.
Protecting against phishing
The front line of any organisation’s defences is the employees, who are worryingly vulnerable. Phishing exploits social engineering, so vigilance is crucial, especially amongst privileged users with access to sensitive information.
Here are some tips to help protect your staff and secure your organisation:
- Train employees to recognise phishing: Implement a red team to identify vulnerabilities, simulate attacks, and raise awareness. Encourage employees to inspect any unusual emails, SMS messages, or calls. Verify urgent requests through separate channels.
- Deploy phishing-resistant MFA: Prevent unauthorised access by using MFA requiring a passkey accessible only via face or fingerprint identification.
- Use UEBA and SOAR for proactive detection and response: Employ SIEM tools with UEBA to spot anomalies based on customisable behavioural variables. ML-driven SOAR platforms can automate responses and assign tickets to security admins.
- Monitor privileged users: Apply the principle of least privilege, train users to be cautious, and monitor their activities for unusual behaviour.
An organisation’s security is only as strong as its weakest link, so every organisation must take urgent steps to address phishing and protect its most valuable asset: employees.





