Ask someone to picture a cyber attack and the image is usually technical: an attacker in a dark room breaking through a defence.
Many incidents begin somewhere less dramatic. A person receives a normal-looking request and is persuaded to click, reset, scan or pay.
The government's Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced phishing. Among businesses that identified any breach or attack, 51% experienced phishing and no other type measured by the survey.
Social engineering is not the only route into an organisation. In M-Trends 2026, exploitation was the most common initial infection vector across Mandiant's investigated intrusions. This article focuses on four everyday requests that small organisations can control with a simple verification process.
1. The email
Phishing is still the most common type of breach or attack identified by businesses in the government survey, but much of the old spotting advice is unreliable.
Bad spelling, clumsy grammar and an odd sender address can be warning signs. Their absence proves nothing. Messages can be polished, tailored to your industry or sent from a genuinely compromised supplier, customer or colleague account.
The more reliable signal is what the message asks you to do. Any unexpected request to move money, change bank details, restore access, disclose information or open something deserves an independent check, however convincing the writing and branding appear.
2. The phone call
A caller says they are an employee who has lost a phone or been locked out. They know enough internal detail to sound convincing and ask for a password or MFA reset.
Reporting around the 2025 UK retail incidents discussed social engineering against IT helpdesks, but the NCSC said there were still many unknowns and did not confirm that as the cause of a particular incident. Its recommendations following the retail incidents nevertheless tell organisations to review how helpdesks authenticate staff before resetting passwords, especially for privileged accounts.
The lesson applies even if you do not have a formal helpdesk. Anyone able to restore access to an account can be socially engineered into granting it.
Treat a password or MFA reset as a new grant of access. Verify it accordingly.
3. The QR code
Microsoft's Q1 2026 email telemetry recorded QR-code phishing volumes increasing from 7.6 million in January to 18.7 million in March, a 146% increase over the quarter. Those numbers describe Microsoft's observed email threats, not the prevalence of QR phishing across every UK business.
Attackers use QR codes because the destination is not visible in ordinary text and the code can move the person from a managed work computer to a phone with different protections. Codes may appear in an email body, inside a PDF or on a printed sticker placed over a legitimate code.
The NCSC's QR-code advice recommends caution with QR codes in email, using the scanner built into your phone, and being suspicious if a site or follow-up contact asks for more information than feels necessary.
Treat a QR code as a concealed link, not as proof that the destination is trusted.
4. The invoice or payment change
An attacker who gains access to a mailbox may read conversations, learn which suppliers are used and wait for a genuine invoice. They can then alter the bank details or send a change request from the compromised account.
The supplier can be real. The amount can be expected. The email history can be genuine. There may be no spelling error or suspicious logo to spot.
That is why payment verification cannot depend on whether an invoice “looks right”. It needs a separate rule.
What the four requests have in common
The email asks you to click or disclose. The phone call asks for a reset. The QR code asks you to scan. The invoice asks you to make a payment you may already expect.
All four try to turn ordinary work into the attacker's next step. Awareness software and filters help, but no person will identify every convincing request on appearance alone.
The most useful control is a standing verification rule.
The rule
Any unexpected request to move money, change bank details or restore access is verified through a separate trusted channel using contact details you already hold.
Call the number in your own supplier record, not a number in the message or on the changed invoice. Contact the employee through the normal directory, not the new number supplied during the reset request. Open the known banking or identity application yourself rather than following a link or QR code.
This rule reduces the risk across all four routes because it does not depend on detecting the attack. It still needs sensible payment approvals, secure accounts and technical controls, and it cannot prevent every form of cyber intrusion.
For the sign-in side of that control, read why MFA isn't enough on its own.
Make the rule work under pressure
Make it standing, not discretionary. If verification is a judgement call, someone must decide under pressure whether a director or supplier sounds slightly wrong. Apply the rule every time the trigger occurs.
Make it safe to use upwards. Your newest employee should be able to verify a request from a director without being criticised for slowing it down. Leaders need to say that explicitly.
Remove artificial urgency. No payment, reset or bank-detail change should be too urgent for a two-minute check. Pressure to bypass the process is itself a warning.
Protect the second channel. A callback only helps if the stored record is trustworthy and access to change it is controlled. Review supplier and staff contact records rather than accepting new details from the request being verified.
Give people somewhere to report
Only 19% of UK businesses ran any cyber security training or awareness session in the previous twelve months, falling to 14% among micro businesses, while 72% said cyber security was a high priority for senior management.
Close that gap with short, realistic examples drawn from the requests your team sees: a supplier changing bank details, a caller asking for a reset, an urgent message from a director or a QR code leading to a login page.
Then provide one named internal reporting route. Make it clear that reporting a harmless message is a good outcome, not an embarrassment. A message that reached one person may be waiting in several other inboxes.
Report suspicious emails, calls, text messages, social-media accounts and websites through Report Fraud's suspicious-report route when no money has been lost and you have not responded. If money has been lost or a live organisational cyber attack is under way in England, Wales or Northern Ireland, use Report Fraud or call 0300 123 2040. In Scotland, contact Police Scotland on 101.
The aim is not to turn every employee into an investigator. It is to make three high-risk actions—money movement, bank-detail changes and account recovery—pause automatically until somebody verifies them through a route the attacker does not control.
If you think an attack is already under way, move to the first-hour cyber attack checklist.