Skip to main content
Practical guidePeople and account security8 min read

How Cyber Attacks Often Start

Four ordinary-looking email, phone, QR-code, and invoice requests attackers use—and a separate-channel verification rule that reduces the risk without relying on perfect detection.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 12 November 2026

At a glance

Independently verify payment, bank-detail and account-recovery requests through a trusted channel.

On this pageArticle contents

Share this article

LinkedInEmail

Ask someone to picture a cyber attack and the image is usually technical: an attacker in a dark room breaking through a defence.

Many incidents begin somewhere less dramatic. A person receives a normal-looking request and is persuaded to click, reset, scan or pay.

The government's Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced phishing. Among businesses that identified any breach or attack, 51% experienced phishing and no other type measured by the survey.

Social engineering is not the only route into an organisation. In M-Trends 2026, exploitation was the most common initial infection vector across Mandiant's investigated intrusions. This article focuses on four everyday requests that small organisations can control with a simple verification process.

1. The email

Phishing is still the most common type of breach or attack identified by businesses in the government survey, but much of the old spotting advice is unreliable.

Bad spelling, clumsy grammar and an odd sender address can be warning signs. Their absence proves nothing. Messages can be polished, tailored to your industry or sent from a genuinely compromised supplier, customer or colleague account.

The more reliable signal is what the message asks you to do. Any unexpected request to move money, change bank details, restore access, disclose information or open something deserves an independent check, however convincing the writing and branding appear.

2. The phone call

A caller says they are an employee who has lost a phone or been locked out. They know enough internal detail to sound convincing and ask for a password or MFA reset.

Reporting around the 2025 UK retail incidents discussed social engineering against IT helpdesks, but the NCSC said there were still many unknowns and did not confirm that as the cause of a particular incident. Its recommendations following the retail incidents nevertheless tell organisations to review how helpdesks authenticate staff before resetting passwords, especially for privileged accounts.

The lesson applies even if you do not have a formal helpdesk. Anyone able to restore access to an account can be socially engineered into granting it.

Treat a password or MFA reset as a new grant of access. Verify it accordingly.

3. The QR code

Microsoft's Q1 2026 email telemetry recorded QR-code phishing volumes increasing from 7.6 million in January to 18.7 million in March, a 146% increase over the quarter. Those numbers describe Microsoft's observed email threats, not the prevalence of QR phishing across every UK business.

Attackers use QR codes because the destination is not visible in ordinary text and the code can move the person from a managed work computer to a phone with different protections. Codes may appear in an email body, inside a PDF or on a printed sticker placed over a legitimate code.

The NCSC's QR-code advice recommends caution with QR codes in email, using the scanner built into your phone, and being suspicious if a site or follow-up contact asks for more information than feels necessary.

Treat a QR code as a concealed link, not as proof that the destination is trusted.

4. The invoice or payment change

An attacker who gains access to a mailbox may read conversations, learn which suppliers are used and wait for a genuine invoice. They can then alter the bank details or send a change request from the compromised account.

The supplier can be real. The amount can be expected. The email history can be genuine. There may be no spelling error or suspicious logo to spot.

That is why payment verification cannot depend on whether an invoice “looks right”. It needs a separate rule.

What the four requests have in common

The email asks you to click or disclose. The phone call asks for a reset. The QR code asks you to scan. The invoice asks you to make a payment you may already expect.

All four try to turn ordinary work into the attacker's next step. Awareness software and filters help, but no person will identify every convincing request on appearance alone.

The most useful control is a standing verification rule.

The rule

Any unexpected request to move money, change bank details or restore access is verified through a separate trusted channel using contact details you already hold.

Call the number in your own supplier record, not a number in the message or on the changed invoice. Contact the employee through the normal directory, not the new number supplied during the reset request. Open the known banking or identity application yourself rather than following a link or QR code.

This rule reduces the risk across all four routes because it does not depend on detecting the attack. It still needs sensible payment approvals, secure accounts and technical controls, and it cannot prevent every form of cyber intrusion.

For the sign-in side of that control, read why MFA isn't enough on its own.

Make the rule work under pressure

Make it standing, not discretionary. If verification is a judgement call, someone must decide under pressure whether a director or supplier sounds slightly wrong. Apply the rule every time the trigger occurs.

Make it safe to use upwards. Your newest employee should be able to verify a request from a director without being criticised for slowing it down. Leaders need to say that explicitly.

Remove artificial urgency. No payment, reset or bank-detail change should be too urgent for a two-minute check. Pressure to bypass the process is itself a warning.

Protect the second channel. A callback only helps if the stored record is trustworthy and access to change it is controlled. Review supplier and staff contact records rather than accepting new details from the request being verified.

Give people somewhere to report

Only 19% of UK businesses ran any cyber security training or awareness session in the previous twelve months, falling to 14% among micro businesses, while 72% said cyber security was a high priority for senior management.

Close that gap with short, realistic examples drawn from the requests your team sees: a supplier changing bank details, a caller asking for a reset, an urgent message from a director or a QR code leading to a login page.

Then provide one named internal reporting route. Make it clear that reporting a harmless message is a good outcome, not an embarrassment. A message that reached one person may be waiting in several other inboxes.

Report suspicious emails, calls, text messages, social-media accounts and websites through Report Fraud's suspicious-report route when no money has been lost and you have not responded. If money has been lost or a live organisational cyber attack is under way in England, Wales or Northern Ireland, use Report Fraud or call 0300 123 2040. In Scotland, contact Police Scotland on 101.

The aim is not to turn every employee into an investigator. It is to make three high-risk actions—money movement, bank-detail changes and account recovery—pause automatically until somebody verifies them through a route the attacker does not control.

If you think an attack is already under way, move to the first-hour cyber attack checklist.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is independent and is not affiliated with or endorsed by the NCSC, ICO, Report Fraud, or any source linked here. This article is general guidance, not legal, regulatory, financial, or incident-response advice.

Clarifications

Frequently asked questions

Do most cyber attacks start with phishing?
Phishing is the most common attack type identified by businesses in the UK government survey, but it is not the only entry route. Exploited vulnerabilities, stolen credentials, malware, remote services, insiders, and suppliers also matter.
How should a business verify changed bank details?
Call the supplier using a number already held in a trusted record, not one in the change request or invoice. Require the same independent check every time, even when the message comes from a familiar account and looks genuine.
Why are QR codes used for phishing?
A QR code conceals the destination in an image and can move the person onto a phone that may sit outside company controls. Be especially cautious when a code leads to a login or payment; open the known app or official site yourself instead.
Where should suspicious emails and texts be reported?
Use Report Fraud's suspicious-report route when no money has been lost and you have not responded, and also use your organisation's internal reporting route. If money is lost or a live organisational cyber attack is under way, use the current police and Report Fraud routes; in Scotland, contact Police Scotland.

Relevant RightCyber product

RightCyber Adaptive Learning

Build cyber security awareness through one adaptive course and receive a completion certificate when the course is complete.

Keep exploring

Browse the RightCyber Blog
  • People and account security

    Why MFA Isn't Enough on Its Own

    MFA still blocks a huge amount of password abuse, but phishable prompts and stolen sessions remain. Move important accounts towards passkeys or FIDO2, then review recovery, session controls, and monitoring.

  • Resilience and incident response

    What to Do in the First Hour of a Cyber Attack

    Put one person in charge, contain the incident without making evidence loss automatic, start trusted calls and a time-stamped record, stop suspicious payments, and assess each reporting duty separately.

  • Resilience and incident response

    Why Small Businesses Get Attacked

    Small firms can be reached by automated attacks and by disruption to organisations they depend on. Map critical suppliers, protect important accounts, test restoration, plan for serious downtime, and resolve incidents fully.