Phishing remains one of the most common and most successful methods used by cybercriminals to gain access to business systems, steal data, and compromise accounts. Despite increased awareness, it continues to work because the techniques keep evolving and the emails keep getting more convincing.
This guide explains what phishing is, which brands are being impersonated right now, how to spot a phishing attempt, and what businesses can do to reduce their exposure.
What Is Phishing?
Phishing is an attempt to deceive someone into revealing sensitive information, such as passwords, payment details, or login credentials, by pretending to be a trusted organisation or individual. The most common method is email, but phishing also occurs via text message, phone calls, and increasingly through QR codes, a technique known as quishing.
The attacker typically creates a sense of urgency, a payment has failed, your account has been compromised, action is required today, and directs the recipient to a fake website that closely mimics a real one. Any information entered on that site goes directly to the attacker.
Which Brands Are Being Impersonated Right Now
Attackers do not choose brands at random. They target the names that people recognise, use daily, and instinctively trust. According to the Check Point Q2 2026 Brand Phishing Report, the top five most impersonated brands globally are Microsoft, LinkedIn, Google, Apple, and Amazon, which together account for more than half of all brand phishing attempts recorded in the quarter.
Microsoft remained the single most impersonated brand, appearing in nearly one in four of all brand phishing attempts. For the first time, ChatGPT entered the top ten most impersonated brands, signalling that AI tools are now firmly on criminals’ radar.
In the UK specifically, the NCSC flagged a significant rise in credential-harvesting campaigns impersonating HMRC, major high-street banks, and NHS digital services in early 2026. UK data also shows parcel delivery services as the most impersonated industry domestically, with Evri and Royal Mail among the most reported impersonated brands.
The practical implication for businesses is that an email appearing to come from Microsoft, a bank, HMRC, or a delivery company is not automatically trustworthy. These are exactly the brands attackers choose because they are the ones people are least likely to question.
How to Spot a Phishing Email
Phishing emails have become significantly more sophisticated. Many are now grammatically correct, visually convincing, and personalised with the recipient’s name or organisation. That said, consistent tells remain.
Check the sender address carefully
The display name may say Microsoft or HMRC, but the actual sending address will often reveal the deception. Look at the full email address, not just the name shown in your inbox. A legitimate email from Microsoft will come from a microsoft.com domain. Anything else is a red flag.
Hover over links before clicking
Before clicking any link in an email, hover over it to see the actual destination URL. If the link text says ‘sign in to your account’ but the URL points to an unfamiliar domain, do not click it. Fraudulent URLs often use slight misspellings or extra characters to appear legitimate.
Be suspicious of urgency
Phishing emails rely on prompting quick action before the recipient thinks critically. Phrases like ‘your account will be suspended’, ‘immediate action required’, or ‘you have 24 hours to respond’ are designed to bypass careful thinking. Legitimate organisations rarely demand instant action via email.
Look for visual inconsistencies
Distorted logos, dead buttons, mismatched social links, and urgent language are usually present in phishing emails if you know to look for them. A legitimate company email will also typically address you by name rather than ‘Dear Customer’ or ‘Dear User.’
Check where links actually go
If you do click a link and reach a website, check the URL in your browser address bar before entering any information. Look for the padlock icon and a domain that matches the legitimate organisation exactly. A padlock alone is not sufficient as fraudulent sites can also hold security certificates.
The Growing Threat of Business Email Compromise
Beyond standard phishing, businesses face a more targeted threat in Business Email Compromise. BEC is a sophisticated form of phishing in which criminals impersonate a senior executive, CFO, CEO, or legal partner to trick employees into transferring funds or sharing sensitive data. What makes BEC particularly dangerous is that no malware is involved, meaning traditional antivirus tools will not flag it.
BEC attacks are typically preceded by research. The attacker studies the organisation, identifies who has financial authority, and sends a convincing request that mimics internal communication. Verifying any unusual financial request by phone, using a known number rather than one provided in the email, is one of the most effective defences.
How to Protect Your Business
Awareness is the first line of defence but it cannot stand alone. A layered approach to phishing protection covers both the human and the technical.
Email filtering and security
Advanced email filtering catches the majority of phishing attempts before they reach an inbox. This includes scanning for malicious links, checking sender reputation, and flagging emails that fail authentication checks. This should be configured and maintained by your IT provider rather than relying on default settings.
Multi-factor authentication
Even if an attacker obtains a password through a successful phishing attempt, multi-factor authentication prevents them from using it to access accounts. Enabling MFA across all business accounts, particularly email, is one of the most impactful steps a business can take.
Staff training
Technical controls reduce the volume of phishing emails that reach staff but they do not eliminate it entirely. Regular, practical training that shows employees what current phishing attempts actually look like is essential. One click on a convincing phishing email can be enough to compromise an entire network.
Keep software up to date
Phishing attacks often direct users to sites that attempt to exploit browser or software vulnerabilities. Keeping operating systems, browsers, and applications updated reduces the risk that a successful phishing attempt causes wider damage.
Report suspicious emails
The NCSC’s Suspicious Email Reporting Service allows anyone to forward suspicious emails to report@phishing.gov.uk. Reports help the NCSC identify and take down fraudulent sites. The NCSC’s Takedown Service removed over 1.2 million phishing and scam campaigns in a recent period, with half taken down within an hour of detection.
What to Do If You Think You Have Been Phished
If you suspect a phishing email has been acted on, whether a link has been clicked, credentials entered, or a payment made, act quickly.
- Change the password for any account that may have been compromised immediately
- Contact your IT provider or security team without delay
- If a payment has been made, contact your bank as soon as possible
- Report to Action Fraud at actionfraud.police.uk
- Check haveibeenpwned.com to see whether your email address has appeared in known data breaches
The faster the response, the greater the chance of limiting the damage.
Concerned about phishing threats to your business?
Techrelate helps businesses across London and the UK put the right email security, staff training, and technical controls in place to reduce their exposure to phishing and other cyber threats. Get in touch: techrelate.co.uk/contact



