Phishing & Social Engineering in 2026
Learn how criminals manipulate people into revealing information, transferring money or opening malicious content.
Phishing attacks target people rather than just technology. Attackers use urgency, fear, authority and trust to influence their victims.
What Is Phishing?
Phishing is a fraudulent message designed to look as though it comes from a trusted person or organisation. It may arrive by email, text message, telephone, social media or a workplace collaboration platform.
Common Social Engineering Techniques
- Fake urgent payment requests.
- Impersonation of managers or suppliers.
- Fraudulent password-reset messages.
- Fake technical support requests.
- Messages containing malicious links or attachments.
- Requests to change supplier bank details.
Pause Before You Act
A message that creates unusual pressure should be treated carefully. Verify the request using a separate trusted communication method.
Warning Signs of a Phishing Message
- An unexpected request for sensitive information.
- A link leading to an unfamiliar website.
- Unusual urgency or threats.
- An unexpected attachment.
- A request to bypass normal procedures.
- Changes to payment instructions.
How Employees Should Respond
- Stop and review the request carefully.
- Check the sender’s address.
- Do not open unexpected attachments.
- Visit websites by typing the address manually.
- Confirm unusual financial requests independently.
- Report suspicious messages immediately.
Create a Positive Reporting Culture
Employees should be encouraged to report mistakes quickly. Fast reporting gives the organisation more time to reset passwords, block messages and prevent further damage.
Good security awareness is about creating careful habits, not blaming employees.