Phishing and Social Engineering: A Guide for Every Employee
A practical, all-employee guide to spotting phishing, vishing and business email compromise scams — and exactly what to do if you click something suspicious.
Most cyber attacks don't start with clever code — they start with a message that looks ordinary enough to trust. An email that appears to be from your manager. A text about a missed delivery. A phone call from "IT support" asking you to confirm your login. These are phishing and social engineering attacks, and they remain the single biggest way organisations get breached. This guide explains how they work, the red flags to watch for, and exactly what to do if you suspect you've been targeted.
Why Phishing Is Still the Number One Cyber Threat
Phishing isn't a niche risk — it's the default one. The UK government's Cyber Security Breaches Survey 2025/26 (gov.uk) found that phishing remained the most prevalent type of breach or attack by far, experienced by 38% of UK businesses in the past 12 months, more than any other attack type. Among businesses that reported any breach at all, phishing was increasingly the only type they encountered — rising from 45% to 51% year on year. The National Cyber Security Centre (NCSC), the UK's authority on cyber security, is equally direct in its own guidance: phishing is the most common way attackers gain an initial foothold in an organisation, precisely because it targets people rather than systems.
That's the core point of this guide. Firewalls, spam filters and antivirus software all help, but a determined attacker only needs one person to click, reply, or hand over a code. Cyber risk is a human-factor risk as much as a technical one — which makes every employee, in every role, part of the defence.
How Phishing and Social Engineering Attacks Work
Social engineering is the umbrella term for manipulating people into taking an action that helps an attacker — clicking a link, opening a file, transferring money, or revealing a password. Phishing is simply the most common delivery method. Here are the variants employees encounter most often.
Email phishing
Mass, untargeted emails sent to thousands of addresses at once, designed to look like they're from a bank, delivery company, software provider or well-known brand. They typically create urgency ("your account will be suspended") and push you toward a fake login page or an infected attachment.
Spear phishing
A targeted version aimed at a specific person or team, using details gathered from LinkedIn, company websites or previous data breaches to feel personal and credible — referencing a real colleague, project or supplier by name. Because it's tailored, spear phishing is harder to spot and far more effective than generic phishing.
Vishing (voice phishing)
Phone-based social engineering, often impersonating IT support, a bank's fraud team, or a senior executive. Attackers use urgency and authority to pressure targets into reading out a one-time passcode, installing remote-access software, or approving a payment. Increasingly, attackers also use AI voice-cloning tools to imitate a real manager's or director's voice, which is worth understanding alongside broader workplace shifts covered in Learnsignal's piece on what employees need to know about AI in the workplace.
Business Email Compromise (BEC)
One of the most financially damaging forms of attack. An attacker either spoofs or actually gains access to a senior employee's mailbox — often a director, finance lead or supplier contact — and uses it to request an urgent bank transfer, a change to supplier payment details, or sensitive data. BEC emails usually contain no malicious link or attachment at all, which is exactly why they slip past technical filters and rely entirely on the recipient trusting the sender.
MFA-bypass tactics
Multi-factor authentication (MFA) — proving your identity with something beyond a password, like a code or approval prompt on your phone — is one of the strongest defences available, but attackers have developed ways around it:
- MFA fatigue (prompt bombing): repeatedly triggering login approval requests until a tired or distracted user taps "approve" just to make them stop.
- Adversary-in-the-middle (AiTM) phishing: a fake login page that silently captures both your password and your live session, letting the attacker bypass MFA entirely.
- SIM swapping: tricking or bribing a mobile provider into moving your phone number to the attacker's SIM, intercepting SMS codes.
- Help-desk social engineering: calling IT support and impersonating an employee to have MFA reset or disabled.
The takeaway: MFA reduces risk significantly, but it isn't a silver bullet — never approve a login prompt you didn't just trigger yourself.
Red Flags to Watch For
No single sign guarantees an attack, but these patterns, especially in combination, should slow you down:
- Urgency and pressure — "act now," "final notice," a deadline within the hour, or a request to bypass normal approval steps.
- Unusual sender details — a display name that looks right but an email address that's slightly off (extra letters, a different domain, a look-alike character).
- Requests that break normal process — a payment, password reset or data request that skips the usual channel or approver.
- Generic or oddly worded greetings — "Dear Customer" from a service that would normally use your name, or phrasing that doesn't sound like the person it claims to be from.
- Unexpected attachments or links — particularly invoices, shipping documents, or "shared files" you weren't expecting.
- A change in payment or account details — especially from a supplier or colleague, arriving by email or text rather than a verified call.
- Requests for MFA codes or login approval — no legitimate IT team or service will ever ask you to read out a one-time code.
What to Do If You Suspect an Attack — or Have Already Clicked
Speed matters far more than embarrassment. The single biggest mistake employees make is staying quiet because they're worried about getting in trouble — this is exactly what gives an attacker time to do damage.
- Don't interact further. Don't click additional links, reply, forward, or enter any more information.
- Report it immediately to your IT or security team through the official channel your organisation provides, even if you're not certain it's malicious.
- If you've entered a password, change it straight away on a trusted device, and change it anywhere else you reuse it (you shouldn't, but many people do).
- If you've approved an MFA prompt or read out a code you didn't request, tell IT immediately so they can lock down the account — this is time-critical.
- If money has been sent following a suspicious instruction, contact your finance team and bank immediately; early reporting significantly improves the chance of recovering funds.
- For a suspicious text message, UK guidance from the NCSC allows you to forward it free of charge to 7726, which helps mobile networks identify and block scam senders.
- For a suspicious email, the NCSC's Suspicious Email Reporting Service accepts forwarded reports at report@phishing.gov.uk, in addition to reporting internally at work.
None of this depends on being a technical expert. It depends on noticing something felt off, and saying so quickly.
The Human Factor: Why People Are the Real Front Line
It's tempting to think of cyber security as an IT problem, solved by better software. In practice, the evidence points the other way: most breaches begin with a person being deceived, not a system being hacked. That's not a criticism of employees — it's a reflection of how effective, and how deliberately designed, modern social engineering has become. Attackers exploit trust, urgency and routine, which means the best defence is a workforce that pauses, verifies, and reports rather than one that never makes a mistake.
This matters just as much for people working from home or split across office and remote settings, where quick verbal confirmation from a colleague sitting nearby isn't always possible — a point covered in more depth in Learnsignal's guide to secure remote and hybrid working policies. Building that habit of healthy scepticism is a skill, and like any workplace compliance skill, it benefits from regular, practical training rather than a single induction session — something worth exploring through Learnsignal's CPD courses.
FAQ
How can I verify a request that seems suspicious?
Contact the person or organisation through a channel you already know is genuine — a phone number from your own records or company directory, not one provided in the suspicious message itself. For payment or account-detail changes, always verify by phone using a known number before acting.
What's the difference between phishing and spear phishing?
Phishing is sent broadly to many people with generic content. Spear phishing is targeted at a specific individual or team using researched, personal details, which makes it more convincing and considerably harder to spot.
I clicked a link but didn't enter any details — am I still at risk?
Possibly. Some malicious links attempt to install malware simply by loading the page. Report it to IT regardless, so they can check your device and the wider network.
Will I get in trouble for reporting a false alarm?
No — reporting something that turns out to be harmless is exactly the behaviour organisations want to encourage. The real risk is staying silent about something that turns out to be real.
Phishing works by exploiting trust and urgency, not technical weakness — which means the strongest defence is a workforce that knows what to look for and feels safe reporting it fast.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


