Phishing remains one of the biggest cyber security threats facing North West SMEs today. Whether you're running a manufacturing business in Greater Manchester, an accountancy practice in Lancashire, a law firm in Cheshire, or a growing business in Merseyside, cyber criminals are increasingly targeting people rather than technology.
Many SME owners assume cyber attacks are aimed at large enterprises with valuable data and deep pockets. The reality is that small and medium-sized businesses are often viewed as easier targets because they typically have fewer dedicated cyber security resources and less time to focus on cyber risk.
The good news? Understanding how modern phishing attacks work is one of the most effective ways to reduce risk and protect your business.
A phishing attack is a cyber crime technique designed to trick people into revealing sensitive information, downloading malicious software or approving fraudulent actions.
Attackers often pretend to be:
Their goal is usually to:
Phishing attacks have become increasingly sophisticated, making them much harder to spot than the obvious scam emails many people associate with cyber crime.
closer, you'll notice the address at the bottom isn't HubSpot's official address
- in fact it's a residential 4 bedroom house!
Cyber criminals are opportunists. They look for businesses that are busy, stretched for time and less likely to have dedicated cyber security teams. For many North West SMEs, staff wear multiple hats. Finance teams process payments, directors juggle operational responsibilities and employees often work across several systems throughout the day. Attacks exploit this environment by creating messages that look urgent, familiar and legitimate.
A single compromised account can give cyber criminals access to:
That access can then be used to steal information, commit fraud or launch ransomware attacks.
One of the most common phishing tactics affecting SMEs today involves fake Microsoft 365 login pages.
The attacker sends an email claiming:
When the user clicks the link, they're taken to what appears to be a genuine Microsoft login page. Once credentials are entered, attackers gain access to the account.
Most SMEs rely heavily on Microsoft 365 for:
A compromised Microsoft account can become the gateway to a significant cyber incident.
Always access Microsoft services through official bookmarks or by typing the address directly into your browser rather than clicking unexpected links.
Many North West SMEs regularly process supplier invoices and payment requests. Cyber criminals know this. Invoice fraud attacks involve criminals impersonating suppliers and requesting payments be sent to alternative bank accounts.
These emails often appear highly convincing, using:
Without proper verification processes, businesses can mistakenly transfer funds directly to criminals.
Be cautious when receiving:
A quick phone call to a known contact can often prevent costly mistakes.
Business Email Compromise (BEC) attacks are becoming increasingly common among SMEs. Cyber criminals impersonate business owners, managing directors or senior leaders and send urgent requests to employees.
The message often asks for:
Because the request appears tom come from someone senior, employees may feel pressures to act quickly without questioning it.
A finance assistant receives an email that appears to be from the Managing Director requesting an urgent same-day payment to support a confidential project. The request feels unusual, but the combination of urgency and authority can lead people to override normal processes.
No payment request should bypass established verification procedures, regardless of who appears to have sent it.
QR codes have become increasingly popular in business communications. Unfortunately, attacks are now using them as part of phishing campaigns. Instead of embedding a malicious link in an email, cyber criminals include a QR code that directs users to a fraudulent website.
Employees often scan the code using personal devices, bypassing company security controls entirely.
As QR code usage grows, so does the need for employee awareness. Ensure when you're scanning a QR code it's from a reliable source.
Many North West SMEs have implemented MFA to strengthen security. While this is a hugely positive step, attackers have adapted. In an MFA fatigue attack, criminals repeatedly trigger authentication notifications hoping the user eventually approves one out of frustration or confusion.
Unexpected MFA prompts should always be treated as suspicious.
While phishing emails are becoming more convincing, there are still common warning signs.
Attackers want people to make quick decisions without thinking. Be cautious of messages demanding immediate action.
Legitimate companies rarely ask for passwords or sensitive information via email.
Hover over links before clicking them to verify the destination.
Be cautious when someone asks you to bypass established business processes.
Even well-crafted phishing emails can sometimes contain subtle wording inconsistencies.
There's no single solution that eliminated phishing risk entirely. The most effective approach combines people, processes and technology.
Staff should understand:
Regular training helps keep awareness levels high.
MFA remains one of the most effective ways to reduce account compromise risk.
Advanced email filtering solutions can identify many threats before they reach inboxes.
Employees should know exactly what to do if they suspect a phishing attempt.
Periodic assessment can help identify vulnerabilities before cyber criminals do.
Can you answer "Yes" to the following?
If the answer is "No", there may be opportunities to strengthen your cyber resilience.
Phishing attacks continue to evolve because they rely on human behaviour rather than technical vulnerabilities. For North West SMEs, the challenge isn't just preventing attacks. It's building a culture where employees recognise threats, follow processes and feel confident reporting concerns. Business that combine staff awareness, modern security controls and proactive IT support are far less likely to become victims of phishing-related cyber incidents.
The goal isn't perfection. The goal is making your business much harder to target.