Security Stop-Press : LastPass Warns Customers Over Vault Backup Phishing Scam

Popular password management service, LastPass, has issued an alert after customers were targeted in a phishing campaign designed to steal account credentials using fake maintenance warnings.

The campaign began around 19 January and involves emails falsely claiming that LastPass is about to carry out system maintenance. Recipients are urged to back up their password vaults within 24 hours, a tactic intended to create urgency and prompt rushed action.

LastPass said the emails use multiple sender addresses and subject lines such as “LastPass Infrastructure Update: Secure Your Vault Now”. Links in the messages lead to a convincing fake website, initially hosted via an Amazon S3 bucket, before redirecting users to a spoofed LastPass login page designed to capture master passwords.

The company stressed it will never ask users to back up vaults or share master passwords by email. The timing of the campaign over a US holiday weekend suggests attackers were attempting to delay detection and extend the lifespan of the scam.

For businesses and other users, the alert is a reminder to be wary of urgent security emails, avoid clicking embedded links, and access LastPass only through its official website or app.

Featured Article : 77% of Security Leaders Would Sack Phishing Victims

New research from Arctic Wolf shows that most security leaders say they would sack staff who fall for phishing scams, even as incidents rise and leaders themselves admit to clicking malicious links.

Hardening of Attitudes

Arctic Wolf’s 2025 Human Risk Behaviour Snapshot reveals that 77 per cent of IT and security leaders say they have (or would) sack an employee for falling for a phishing or social engineering scam, up from 66 per cent in 2024. The report describes this shockingly high statistic as the result of a significant hardening of attitudes among security professionals, despite continuing increases in attack volume and breach rates.

The Scale

The study, which surveyed more than 1,700 IT leaders and end users globally, found that 68 per cent of organisations suffered at least one breach in the past year. The UK and Ireland, for example, recorded some of the steepest rises, partly due to high-profile incidents in the retail sector. Arctic Wolf notes that many firms are still failing to implement basic measures, with only 54 per cent enforcing multi-factor authentication (MFA) for all users.

Sacking Doesn’t Solve The Problem

The same report also found that organisations taking an education-first approach rather than firing staff saw an 88 per cent reduction in long-term human risk. According to Arctic Wolf’s Chief Information Security Officer, Adam Marrè, “Terminating employees for falling victim to a phishing attack may feel like a quick fix, but it doesn’t solve the underlying problem.”

A Strong Policy Signal

The findings of the report appear to highlight a growing gap between confidence and capability. For example, three-quarters of leaders said they believed their organisation would not fall for a phishing attack, yet almost two-thirds admitted they have clicked a phishing link themselves, and one in five said they failed to report it.

Corrective Action Instead of Dismissal

It should be noted that, in the same survey, more than six in ten leaders said they had taken corrective action against employees who fell for phishing scams by restricting or changing access privileges, which Arctic Wolf suggests is a more constructive approach than dismissal.

Executives Are Valuable Targets For Cybercriminals

In fact, the company’s own data also shows that 39 per cent of senior leadership teams were targeted by phishing and 35 per cent experienced malware infections, highlighting how executives themselves are often the most valuable targets for attackers.

“When leaders are overconfident in their defences while overlooking how employees actually use technology, it creates the perfect conditions for mistakes to become breaches,” Marrè said. He added that the most secure organisations “pair strong policies and safeguards with a culture that empowers employees to speak up, learn from errors, and continuously improve.”

Confidence Vs Behaviour

The Arctic Wolf report appears to highlight a clear contradiction. For example, while most security leaders view phishing as a frontline employee issue, they are actually statistically among the most likely to make the same mistakes. Many also admit to disabling or bypassing security systems. For example, 51 per cent said they had done so in the past year, often claiming that certain measures “slowed them down” or made their work harder.

This gap between stated policy and personal practice is what Marrè describes as “a major blind spot and degree of hubris among some security leaders.” The report concludes that leadership culture sets the tone for the rest of the organisation, and that inconsistency at the top erodes credibility and weakens defences.

Who Is Really Falling For Phishing In 2025?

The question of who gets caught out most is not as simple as it might appear. For example, Arctic Wolf’s data indicates that senior staff, not junior employees, are often prime targets because of their privileged access and decision-making authority. The company found that nearly four in ten executive teams experienced phishing attempts, compared with lower rates among general staff.

Other research appears to support this pattern. For example, Verizon’s 2025 Data Breach Investigations Report confirms that social engineering remains one of the top causes of data breaches, accounting for more than two-thirds of all initial intrusion methods. Its analysis identifies finance, healthcare, education, and retail as the most heavily targeted sectors. Attackers exploit trust, urgency, and routine workflows to trick users into sharing credentials or downloading malware.

New Hires More Likely To Click

Also, a mid-2025 study by Keepnet, reported by Help Net Security, found that 71 per cent of new hires clicked on phishing emails during their first 90 days, making them 44 per cent more likely to fall victim than longer-serving staff. The main reasons were unfamiliar internal systems, a desire to respond quickly to apparent authority figures, and inconsistent onboarding security training. The same research found that structured, role-specific training reduced click rates by around 30 per cent within three months.

Retail Legacy Systems An Issue

Retail has also seen a marked increase in phishing incidents across the UK and Ireland. Arctic Wolf attributes this to the industry’s reliance on legacy systems, seasonal sales spikes, and the complexity of managing large volumes of customer data. The company says these factors have made retail “a prime target” for opportunistic and scalable attacks.

Can Employers Really Sack Staff For Clicking A Phishing Email?

In the UK, simply sacking an employee for falling for a phishing email is legally possible but rarely straightforward. For example, under the Advisory, Conciliation and Arbitration Service (Acas) Code of Practice, an employer can only dismiss fairly if they have both a valid reason, such as misconduct or capability, and have followed a fair and reasonable procedure.

For a dismissal to be lawful, the employer must investigate properly, give the employee a chance to respond, and ensure the sanction is proportionate. Even where a phishing incident causes financial loss or reputational damage, the question is whether the individual acted negligently or was misled despite reasonable training and policies. In most cases, a first-time mistake caused by deception would not actually meet the threshold for gross misconduct.

Unfair Dismissal?

It’s worth noting here that employees with two years’ service can bring a claim for unfair dismissal if they believe the reason or process was unreasonable. Employment tribunals are required to take the Acas Code into account, and may increase or reduce compensation by up to 25 per cent if either side fails to follow it. This means employers that act punitively without clear evidence or consistent practice could face costly legal challenges.

Most employment lawyers, therefore, recommend a corrective rather than disciplinary response, especially where the organisation’s training or technical safeguards may have been insufficient. Arctic Wolf’s data reflects this tendency, with many leaders actually opting to limit access rights rather than dismiss staff outright after a phishing incident.

Ethics And Culture

Beyond legality, there is an ethical debate here to take account of which focuses on culture and transparency. For example, the UK’s National Cyber Security Centre (NCSC) advises that creating a “no-blame reporting culture” is one of the most effective ways to reduce security risk. Its guidance stresses that employees should feel safe to report suspicious emails or mistakes immediately, without fear of reprisal.

In fact, it is well known that when punishment is the first response, employees often stay silent. Arctic Wolf’s own findings appear to bear this out, i.e., one in five security leaders who clicked a phishing link failed to report it. That silence can allow breaches to escalate before they are detected.

Human Error Inevitable

Security experts argue that treating human error as inevitable, and training people to respond effectively, is far more effective than zero-tolerance policies. Marrè says that “progress comes when leaders accept that human risk is not just a frontline issue but a shared accountability across the organisation.” He advocates regular, engaging training that reflects real threats, backed by leadership example and open communication.

The Double Standard In Practice

The data from this and other reports appears to paint a clear picture of contradiction at the top. For example, many of the same leaders who advocate sacking staff for phishing errors have clicked links themselves or disabled controls that protect the wider organisation. Arctic Wolf’s report describes this as “a culture of ‘do as I say, not as I do’,” warning that it undermines credibility and increases exposure to social engineering attacks.

Phishing Now More Sophisticated

One other important factor to take into account here is the fact that phishing techniques have also grown more sophisticated. For example, attackers now use AI-generated emails, cloned websites, and real-time chat-based scams to trick users into sharing credentials. Even experienced professionals can, therefore, struggle to spot these messages, particularly when they appear to come from known suppliers or senior colleagues.

AI Supercharges Phishing Success

Microsoft’s 2025 Digital Defence Report shows that AI-generated phishing emails are 4.5 times more likely to fool recipients, achieving a 54 per cent click-through rate compared with 12 per cent for traditional scams. The company says this surge in realism and scale has made phishing “the most significant change in cybercrime over the last year”.

Microsoft also estimates that AI can make phishing campaigns up to 50 times more profitable, as attackers use automation to craft messages in local languages, tailor lures, and launch mass campaigns with minimal effort. Beyond email, AI is now being used to scan for vulnerabilities, clone voices, and create deepfakes, transforming phishing into one of the fastest-growing and most lucrative attack methods worldwide.

Initial Compromise Comes From Phishing

Industry-wide data continues to show that phishing is the most common initial attack vector in business email compromise, ransomware, and credential theft cases. Verizon’s latest data shows phishing accounts for roughly 73 per cent of initial compromise methods, followed by previously stolen credentials. These statistics underline how difficult it is to eliminate human error entirely, even in well-trained environments.

Arctic Wolf argues that genuine progress actually requires leading by example rather than blaming employees. In its report, the company’s closing recommendations include continuous education, practical simulations, and building a culture that rewards honesty over silence. Its research concludes that organisations where employees feel confident to report mistakes are significantly less likely to experience repeat incidents, and far more likely to detect breaches early.

What Does This Mean For Your Business?

The findings appear to highlight a cultural challenge within cyber security. Punishing individuals for mistakes that even experienced leaders admit to making risks undermining the very trust and openness that strong defences depend on. The evidence shows that while technical safeguards such as MFA and endpoint protection are essential, they are not enough on their own. What really differentiates resilient organisations is how they handle human error, whether they choose to learn from it or treat it as grounds for dismissal.

For UK businesses, the implications are significant. A strict zero-tolerance policy towards phishing may appear decisive, but it can also damage morale, suppress reporting, and expose employers to potential legal and reputational risks. Dismissing staff without due process could also lead to unfair dismissal claims, while a culture of fear can discourage the transparency needed to contain attacks quickly. By contrast, firms that take a measured, education-focused approach tend to see fewer repeat incidents, faster recovery times, and stronger employee engagement in security.

The message from Arctic Wolf’s data is that leadership example matters most. When senior executives model good cyber hygiene, acknowledge their own vulnerabilities, and support open communication, staff are far more likely to follow suit. Creating an environment where everyone feels responsible for reporting threats, and confident they will be supported for doing so, delivers a far greater return than any punitive measure.

For regulators, investors, training providers and others, the findings reinforce the importance of human-centred strategies that combine accountability with education. As phishing continues to evolve in sophistication, organisations across all sectors must balance clear policy enforcement with a recognition that even the best-informed professionals can make mistakes. The organisations that respond to that reality with fairness, transparency, and leadership integrity will be the ones best equipped to withstand the next wave of attacks.

Back 2 Cyber-School : Test Your Team

UK firms are using summer downtime to run cybersecurity quizzes that improve staff awareness, reduce phishing risks, support onboarding, and build a stronger security culture ahead of the September reset.

Why Summer Is the Time to Act

It may seem counterintuitive to launch a cybersecurity initiative during the holiday season, yet security professionals say this is exactly the right time to do it.

Staff returning from leave are often catching up on emails, resetting routines, and switching back into work mode. That makes them particularly vulnerable to phishing emails, credential theft, and misjudged clicks. For example, according to CybSafe, human error still accounts for 95 per cent of successful cyber attacks, with fatigue, distraction and complacency frequently involved.

A 2024 KnowBe4 report found that staff were 29 per cent more likely to click on phishing links in the first week after returning from time off. With many UK employees taking annual leave during July and August, the September return presents a high-risk window.

That is why many IT and compliance teams are opting to launch a light-touch but high-impact quiz or awareness campaign during summer, or just at the end of the holiday period. The aim is to create a timely reset, not a compliance burden. As CybSafe puts it, “It’s like sharpening the tools before we go back into the busy season.”

Back to Business and Back to Basics

The term “back to school” may be figurative, but the principle stands. September often marks a fresh start, Q4 planning begins, new projects launch, and there is an influx of new joiners or temporary staff.

That makes it a natural moment to remind employees of core cyber hygiene habits. Password security, phishing recognition, two-factor authentication, and safe use of cloud platforms are all common focus areas. Rather than relying on lengthy and formal training sessions, many businesses are shifting towards short and interactive formats that nudge behaviour and boost recall.

Awareness Quizzes

For example, firms including CybSafe, KnowBe4 and ESET now offer ready-made awareness quizzes tailored to workplace risks. These tools test employees’ understanding of phishing techniques, device hygiene, credential security, and social engineering tactics. Many offer features such as internal benchmarking, anonymised scoring by department, and follow-up resources based on quiz performance.

Quizzes typically include multiple choice or scenario-based questions, with questions such as, “You receive a Teams message from your manager with an urgent link to an invoice. What should you do?” Feedback is usually immediate, and correct answers are explained to reinforce good habits.

To be effective, questions need to reflect real-life risks. For example, a phishing section might include, “This email asks you to ‘urgently verify your payroll details’ using a link. What should you check first before clicking?” A password hygiene question could ask, “Which of these is the most secure password: Pa55word!, £S78qp*4, John1980, or MyCompany123?” Other useful topics include recognising suspicious attachments, safe use of public Wi-Fi, and what to do if you suspect your laptop has been compromised.

For remote or hybrid workers, practical scenarios can help highlight overlooked risks. One example might be, “You’re working from a café and need to join a video call. What is the safest way to connect?” By focusing on realistic decisions, these questions build familiarity with threats and give staff confidence to make better choices.

As CybSafe notes, “Security awareness doesn’t need to be dry. Gamification increases engagement by up to 60 per cent, and we see higher retention when people enjoy the format.”

New Staff, New Risks

Another reason why late summer is an ideal time for awareness activity is the volume of onboarding across many sectors. Whether it is school leavers entering the workforce or internal moves following the holiday period, new and transitioning employees are consistently shown to be more vulnerable.

Research cited by Keepnet Labs shows that new hires are 44 per cent more likely to click on phishing links, and 71 per cent more susceptible to social engineering tactics within their first three months. This is often due to unfamiliarity with tools, eagerness to make a good impression, and uncertainty around what constitutes suspicious behaviour.

Embedding a cyber quiz into induction materials or using it as part of a post-holiday reset can help mitigate this. According to Keepnet, “Embedding quizzes into everyday culture, not just annual training, helps build shared ownership of cyber hygiene. Awareness becomes a team asset, not an individual chore.”

Campaigns That Stick

Many UK firms are using seasonal branding and lighter messaging to increase participation. For example, naming the initiative “Back to Business: Cyber Reset” or “Security September” helps frame the content as helpful and timely, rather than bureaucratic.

Typical campaign assets include a short online quiz, accompanying infographics or posters on common threats, and a follow-up message sharing results or next steps. Some businesses use this moment to revisit hybrid working guidance or flag updates to bring-your-own-device (BYOD) policies.

The Cyber Security Breaches Survey 2025, published by the Department for Science, Innovation and Technology, highlights just how common incidents remain. 43 per cent of UK businesses reported a cyber breach or attack in the past 12 months, but among medium-sized businesses, that figure rose to 70 per cent, and for large organisations, to 90 per cent.

The same report found that businesses with regular staff training and awareness campaigns were more likely to detect and respond to threats promptly. That strengthens the case for low-friction, repeatable tools like quizzes, especially when timed around known periods of vulnerability.

Metrics That Matter

It seems that quizzes can also generate useful insights. For example, platforms such as CybSafe and KnowBe4 offer dashboards showing which questions are commonly missed, which teams or roles may need additional support, and how engagement varies over time. That helps IT, HR and compliance teams refine their approach and demonstrate value to leadership.

These insights can also support wider objectives. For companies pursuing Cyber Essentials or ISO 27001 certification, regular awareness campaigns count as demonstrable evidence of good cyber governance and staff engagement with security.

Crucially, quizzes offer an approachable format. For example, as CybSafe research shows, campaigns framed around positive reinforcement rather than fear or punishment consistently lead to better uptake, stronger recall and healthier behaviours across the organisation.

Real-World Findings Underscore the Risk

Recent UK data reinforces the need for continued staff education. In the Cyber Security Breaches Survey 2025, phishing was identified as the most common attack method by 85 per cent of affected businesses. 65 per cent said it was the most disruptive type of incident they faced.

In the SME sector, a study by GetApp UK found that 94 per cent of phishing attacks arrived via email, and more than two-thirds of businesses had faced multiple attempts in a short timeframe. The simplicity of phishing makes it hard to block completely through technical defences, placing the onus back on staff to spot and avoid traps.

Also, the risk is not limited to newcomers. For example, as a UK workplace study reported by Insurance Edge found, managers were twice as likely as junior staff to fall for phishing scams, despite being more familiar with systems and policies. That suggests even experienced employees benefit from regular and practical reminders.

Taken together, these findings reinforce why so many UK businesses are choosing to run fun, quiz-based cyber campaigns during the summer, to catch complacency before it becomes costly.

What Does This Mean For Your Business?

This approach is not about ticking boxes. It’s actually about creating a security culture that works with people, not against them. For example, quizzes seem to offer a simple, low-pressure way to reset expectations, surface knowledge gaps, and refocus attention on the behaviours that actually reduce risk. They are also easy to run and repeat, which gives organisations more flexibility than formal training cycles often allow.

For UK businesses, the benefits are both immediate and long-term. A short, well-timed quiz can reduce phishing risk, especially among returning staff and new joiners, while also demonstrating good governance to customers, insurers and auditors. When supported by the right follow-up and metrics, these tools become part of a wider risk management strategy, not a standalone event. In sectors where compliance, reputation or customer trust are central, that distinction matters.

The impact also extends beyond the IT team. HR departments, line managers and internal communications teams all have a role to play in making cyber awareness relatable and consistent. Using seasonal campaigns or friendly team challenges helps embed these habits across different parts of the business, rather than leaving them siloed. That shift is key if organisations want security awareness to feel like part of the culture, not just a requirement.

Suppliers, partners and clients also benefit from this raised awareness. In an interconnected economy, a weak link in one organisation can expose others to unnecessary risk. By encouraging regular, engaging training, UK firms not only protect their own operations, but also contribute to a more resilient digital environment across their wider supply chain.

The timing matters too. With rising attack volumes and continued pressure on internal resources, companies that take advantage of the quieter summer period to prepare for Q4 are putting themselves on the front foot. Awareness may not stop every attack, but it can make the difference between a quick recovery and a costly incident. That is why summer quizzes are gaining momentum, and why more organisations are choosing to turn a seasonal lull into a strategic advantage.

Summer Phishing Surge: Why Scammers Love Holidays

Here we look at how phishing scams spike in summer, including fake travel bookings, delivery text traps and urgent invoice fraud, and why UK businesses and individuals are especially vulnerable during the summer holiday season.

Phishing Peaks in Summer as Risk Awareness Drops

The summer season is increasingly being exploited by cyber criminals as a prime window to launch targeted phishing campaigns. For example, according to Action Fraud, UK consumers lost over £11.6 million to holiday-related scams in 2024 alone, with July and August seeing the highest volume of reports.

Why?

Experts point to a combination of seasonal distractions and increased online transactions, particularly for travel and leisure, as key drivers. With staff taking annual leave and workflows stretched thin, businesses are also becoming easier prey for invoice fraud and impersonation attempts.

Proofpoint, a global cyber security firm, recently warned that over one third of major UK travel booking platforms are failing to implement basic email authentication protections, such as full DMARC rejection policies, leaving customers vulnerable to spoofed messages. “Criminals know people are more likely to be booking trips or awaiting parcels,” said Adenike Cosgrove, cybersecurity strategist at Proofpoint. “That makes them more likely to click without thinking.”

Fake Travel Sites and Booking Confirmations Are Widespread

A common scam involves fake travel booking websites or emails posing as legitimate platforms such as Booking.com, Airbnb or Jet2. In many cases, victims are lured through paid adverts on social media or search engines, where fraudulent domains are made to closely resemble real travel brands.

In one incident recently flagged on Reddit and verified by multiple users, scammers exploited Booking.com’s internal messaging system to pose as hotels, sending follow-up messages asking guests to confirm payment via a malicious third-party link. The impersonators mimicked the platform’s branding and messaging style with alarming accuracy.

Fake Accommodation Offers

According to Action Fraud, 44 per cent of holiday-related phishing reports in 2024 involved fake accommodation offers. For example, many victims were contacted after initially engaging with a legitimate booking site, suggesting criminals are monitoring and hijacking booking journeys to insert phishing attempts at key points.

Delivery Text Scams Continue to Catch Holidaymakers Off Guard

One of the most persistent phishing threats this summer is smishing, where fraudulent text messages impersonate delivery companies such as Royal Mail, Evri or DPD. These scams typically claim a parcel is delayed or requires a small fee to release, directing the recipient to a fake website that harvests card details or personal information.

The problem is growing. According to Proofpoint and UK Finance, fake parcel delivery texts accounted for 67.4 per cent of all reported smishing attempts in the 30-day period to mid-July 2025, up from 53.2 per cent in previous months. Financial impersonation scams, by comparison, made up just 22.6 per cent over the same period.

This reflects a longer-term trend. The National Cyber Security Centre reported a 174 per cent year-on-year rise in smishing attacks as of mid-2024, and industry data indicates that the increase has continued well into 2025. A recent consumer survey by Ofcom found that 42 per cent of UK mobile users had received a suspicious call or SMS in the past three months.

Mobile Scam Filters Still Falling Short

While mobile operators claim that scam filters are improving, independent testing has raised concerns. In one 2025 study by cyber firm MetaCert, every simulated smishing message was successfully delivered to UK phones. These included texts spoofing well-known brands and containing malicious links, suggesting that current filtering systems are still failing to block even basic threats.

Why Summer Timing Makes These Scams More Effective

The seasonal context plays an important role. During the summer, people are more likely to shop online for travel items, gifts or personal deliveries while away from home. This makes messages about missed or rescheduled parcels seem believable and time-sensitive, creating the urgency that scammers rely on.

According to advice published by Age UK Barnet, for example: “scam texts often appear to come from delivery companies, like Evri or Royal Mail, saying that a parcel is on its way and asking for payment.” The charity warns that people may click without thinking, especially when expecting a delivery, and highlights that older users may be particularly vulnerable if they are unfamiliar with digital services or not used to checking links carefully.

The growing sophistication of these scams, including the use of personalised names, postcodes or local courier references, makes them harder to detect. This is especially true on mobile devices, where links and sender details are less visible at a glance.

Fake Invoices and Business Email Scams Surge Before Holiday Deadlines

For UK businesses, the summer period brings another kind of cyber threat. Business Email Compromise (BEC) and invoice phishing scams often spike around end-of-quarter deadlines or during peak holiday handovers, when key personnel may be absent.

Scammers typically insert themselves into existing email threads by using a near-identical address to impersonate suppliers, contractors or internal staff. They then request urgent payments to altered bank accounts, citing things like updated banking details or changes to invoice terms.

With this in mind, the North East Business Resilience Centre (NEBRC), for example, has issued multiple alerts this summer urging firms to verify payment details verbally before transferring funds. “Organisations should treat every payment change request—no matter how routine it seems—with extreme caution, especially when staff are away,” said the NEBRC’s cyber lead. “We see companies lose tens of thousands of pounds in a single transaction.”

According to UK Finance, invoice and mandate scams cost UK businesses over £56.7 million in a single year, with construction, legal and property sectors among the most targeted.

Quishing Attacks Using QR Codes Are Also on the Rise Too

Perhaps a less familiar but growing trend is the use of malicious QR codes in phishing campaigns, often referred to as “quishing”. These codes may appear in emails, event posters, parking meters or travel itineraries, and lead to malicious websites once scanned.

Security researchers at Check Point have identified a significant increase in such attacks since spring 2025, with many targeting travellers by mimicking airline boarding passes or local information portals.

The real danger lies in the perception of safety associated with QR codes, particularly when presented in a printed or semi-official context. In several recent cases, scammers have replaced public QR codes on transport signage or tourist maps with fake stickers that lead to credential-harvesting sites.

UK businesses operating physical locations or QR-based digital services are being urged to regularly check signage, validate their own codes, and educate staff on the risks of scanning unknown links.

Criminals Exploit Social Context and Emotional Cues

What links all of these attacks is timing and emotional manipulation. For example, summer, with its relaxed atmosphere, frequent purchases and disrupted routines, creates ideal conditions for social engineering.

For example, as cyber security firm Barracuda reports, seasonal phishing emails tend to use more emotionally charged language, including urgency, fear of missing out or appeals to customer service or refunds. Phrases like “Your booking is at risk”“Re-delivery needed today” or “Outstanding invoice requires attention” are designed to provoke rapid reactions.

The NCSC encourages UK users to follow its “Stop, Challenge, Protect” guidance—pausing before clicking or paying, questioning the legitimacy of the request, and reporting suspicious messages to the Suspicious Email Reporting Service (SERS) (at report@phishing.gov.uk).

Many Attacks Are Enabled by Gaps in Email Security

A report by Proofpoint revealed that as of summer 2025, only 61 per cent of the UK’s top 50 travel websites had enforced full DMARC rejection policies, which is a basic email authentication setting that helps prevent domain spoofing. This leaves both individual travellers and business clients exposed to fake emails that appear to come from trusted brands.

Similarly, smaller organisations often lack the cyber hygiene measures to filter out high-risk attachments or check for lookalike domains. In phishing simulations conducted by KnowBe4, UK companies saw click rates of over 33 per cent during peak summer periods, compared to 24 per cent in winter, suggesting seasonal distractions increase user vulnerability.

Also, the British Chambers of Commerce has called on smaller firms to step up basic security practices, especially during holiday periods when decision-making may be rushed or decentralised.

Cybercriminals Are Adapting Faster Than Users Can React

The final concern raised by many experts is the speed with which scammers adapt. While businesses and individuals may learn to spot one kind of scam, attackers quickly switch tactics, changing domain names, targeting new seasonal trends or using AI tools to personalise their phishing lures.

Check Point’s threat intelligence team recently found that Google, Microsoft and Apple were the top three brands impersonated in UK phishing campaigns during Q2 2025. These impersonations often come in the form of bogus security alerts, fake travel subscriptions or seemingly legitimate service confirmations.

The summer of 2025 is no exception. As more people head off on breaks, and companies operate with skeleton crews, phishing attacks are exploiting every opportunity to slip through the cracks.

What Does This Mean For Your Business?

What emerges from this summer’s phishing surge is a clear pattern of opportunism that cuts across both consumer and business behaviour. It seems that cyber criminals are not relying on sophisticated infrastructure or zero-day exploits. Instead, they seem to be exploiting timing, familiarity and human distraction. For UK businesses, especially smaller firms, this creates a persistent operational risk that does not end with the holiday season.

Attacks linked to fake bookings, delivery texts and invoice fraud are not only rising in volume but also in precision. Social engineering tactics have become more convincing, and the tools behind them more accessible. As the examples in this report show, scammers no longer need to breach systems to steal money or data, but they just need to catch someone at the wrong moment with the right message. This is particularly dangerous in summer when staff changes, out-of-office patterns and dispersed decision-making leave more gaps than usual.

The ongoing failure to implement email authentication standards such as DMARC, and the unreliable performance of mobile scam filters, suggest that many organisations are still relying on outdated or partial defences. Without investment in basic technical controls and regular user awareness training, UK businesses will continue to see preventable losses from phishing, whether in the form of misdirected invoice payments, stolen credentials or damaged trust.

For individuals, especially those booking holidays or expecting deliveries, the lesson is equally pressing. The presence of a recognisable brand or a plausible message is no longer a guarantee of safety. Personal vigilance, combined with public reporting and institutional support, will remain critical.

Looking ahead, the challenge is not just seasonal. Cyber criminals will continue to adapt their tactics to whatever events, platforms or behaviours dominate public attention. However, the summer phishing spike is a useful case study in how quickly attackers can exploit simple human habits, and how slow many defences still are to catch up. For both UK organisations and their customers, tackling phishing will require more than just summer warnings. It demands consistent, year-round resilience.

Security Stop-Press: HMRC Hit by £47m Phishing Scam Targeting Taxpayer Accounts

Criminals stole £47 million from HMRC last year by exploiting over 100,000 taxpayer accounts in a major phishing scam.

The fraudsters used stolen personal data to access or create Government Gateway accounts, then submitted fake tax rebate claims. HMRC says no individuals lost personal funds, as the money was claimed directly from its own systems.

“This was an attempt to claim money from HMRC, not from customers,” the authority said. Affected individuals are now being contacted, though many didn’t know they had an account in the first place.

The incident only came to light during a Treasury Select Committee hearing, prompting criticism from MPs. Arrests have been made following an international investigation.

HMRC insists its systems weren’t hacked but has pledged further investment in account security. It blocked £1.9 billion in similar fraud attempts last year.

To guard against similar attacks, businesses should focus on phishing awareness training, enable strong two-factor authentication, and regularly audit account activity for unauthorised access.

Tech Insight : Block Spam Calls

In this Tech Insight, we look at how UK businesses can identify, block, and protect themselves against the growing nuisance (and threat) of spam calls, and why doing so is now essential for productivity, security, and reputation.

More Than a Nuisance

If you’ve noticed more spam calls slipping through lately, you’re not imagining things. Nuisance calls, i.e. from robotic sales pitches to full-blown scam attempts, have become a major source of disruption (and risk) for UK businesses.

In fact, research from Ofcom estimates that UK consumers and businesses receive over 4.4 billion nuisance calls and texts per year, with a significant proportion targeting workplaces. From lost productivity and operational distraction to fraud and reputational damage, spam calls are creating headaches across sectors. For some, they’re also creating serious financial losses.

What Counts As a Spam Call?

Broadly speaking, spam calls refer to any unsolicited or unwanted phone call, particularly those made in bulk. They may originate from real people or bots, domestic numbers or international spoofed lines, and their intentions can range from sales to scams. Common categories include:

– Telemarketing calls. These are usually from legitimate businesses, yet are often annoying and unwanted.

– Robocalls. This type of call uses pre-recorded messages, often tied to fake tech support, medical cover or financial offers.

– Scam calls. These calls are designed to try and trick the recipient into handing over personal or financial information.

– Silent or abandoned calls. These are often used to verify if a number is “live” for future targeting.

Although some spam calls are relatively harmless, many are sophisticated fraud attempts. The UK’s National Cyber Security Centre (NCSC) notes an increasing link between spam calls and cybercrime, including phishing, identity theft, and voice cloning scams.

A Growing Threat to Businesses

Spam calls are no longer just a nuisance to receptionists or front-line teams. For UK companies of all sizes, they can lead to missed leads, disrupted workflows, and even data breaches.

For example, a recent study by Truecaller found that globally, businesses lose an average of $14 billion a year to phone scams. While exact UK figures are harder to isolate, UK Finance reported over £1.2 billion in fraud losses in 2023, with social engineering scams, often initiated via phone, accounting for a large slice.

For example:

– A logistics company in Manchester reported receiving over 20 spoofed calls a day, some impersonating HMRC or customs officers.

– A legal firm in Surrey was conned out of £28,000 after a senior partner unknowingly responded to a voice-phishing scam, believing it was a client confirming bank details.

– An SME in the retail sector said they had to dedicate an admin staff member solely to filtering phone calls, costing them hours of productivity weekly.

As fraud tactics become more advanced, including the use of AI-generated voices and deepfake impersonation, spam calls are quickly evolving from an irritation into a significant security risk.

How Are They Getting Your Number?

One of the most frustrating aspects of spam calls is how widespread and persistent they are, even for numbers that were never shared publicly.

Here’s how they’re likely getting in:

– Data breaches. Your number may have been compromised in a company breach or exposed via a third-party contact.

– Web scraping. Spammers use bots to harvest numbers from websites, contact pages, and social media profiles.

– Number generators. Robocallers simply dial every possible variation of UK numbers using auto-dialling software.

– Data brokers. Some marketing companies sell on contact lists without appropriate consent.

Even legitimate-seeming calls may not be what they appear. Number spoofing allows fraudsters to display fake caller IDs, often mimicking well-known institutions or even internal office numbers.

Why Businesses Need a Serious Defence Strategy

The problem is no longer solvable simply with caller ID alone and, for UK businesses, relying on staff to manually screen calls is unsustainable. Not only does it eat into valuable time, but it also increases the risk of missing genuine client calls.

Instead, a layered and proactive approach is needed. Ideally, this type of approach should include:

– Network-level blocking. All major UK mobile networks (including EE, O2, Vodafone and Three) now offer spam filtering and scam call protection. Some, like O2’s Call Defence, automatically warn users about suspicious numbers. EE flags suspected scam calls in real time.

– Smartphone features. Both Android and iPhone users can activate built-in call blocking and spam detection tools. On Android, turning on ‘Caller ID & spam’ and filtering spam calls will silence known nuisance numbers. On iPhone, enabling ‘Silence Unknown Callers’ sends calls from unknown numbers straight to voicemail – though with the risk of missing new contacts.

– Call screening software. Businesses can deploy dedicated VoIP services or call management apps like Hiya, Truecaller for Business, or BT’s Call Protect to detect, divert and report malicious calls. These platforms often use real-time databases of spam numbers and AI-based filtering to block unwanted calls before they reach a human.

– Staff awareness and call protocols. Employee training is essential. Staff should be reminded never to give sensitive information over the phone unless they can verify the caller. Set up internal rules, such as always calling back a client on a verified number instead of trusting inbound requests.

– Registration with TPS (Telephone Preference Service). UK businesses can also register with the Corporate Telephone Preference Service (CTPS) to legally opt out of receiving marketing calls. While this doesn’t block international spam, it offers some protection from UK-based telemarketers, and gives businesses legal grounds to complain if calls persist.

Common Spam Call Tactics in 2025

Spam calls have evolved. It’s no longer just robotic PPI chasers. Today’s fraudsters are deploying more advanced (and sinister) tricks. For example, watch out for:

– Impersonation scams. Callers claiming to be from HMRC, the bank, Microsoft, or your own IT provider.

– “Can you hear me?” traps. Designed to get a voice recording of you saying “yes”, which can be used to authorise charges or access.

– Fake client inquiries. Scammers pretending to be new customers, asking for personal or operational details.

– Missed call scams. You receive a one-ring call from an international number and calling back triggers premium charges.

There are also increasing reports of AI voice synthesis being used to impersonate real people, including senior managers. These so-called “deep voice” scams are alarmingly convincing and often target finance or HR departments.

Tools and Tech to Help Businesses Fight Back

Fortunately, there are real, actionable tools businesses can use to block, track, and report spam calls. Just some examples of such tools include:

– PhoneSystem (BT, 3CX, RingCentral, etc.). Business-grade phone systems often include spam detection, call screening, and custom call-routing features.

– Spam call reporting portals. Use the ICO’s nuisance call reporting tool and Action Fraud to report malicious activity. This helps build national data for enforcement.

– AI-based call blockers. Tools like Nomorobo, RoboKiller, and Truecaller Premium now cater to UK businesses and use dynamic databases to identify threats in real time.

It’s also worth keeping an eye on Ofcom’s anti-scam call initiatives, including new proposals to limit international number spoofing and force providers to apply stricter blocking at the network level. Telecoms companies must also now verify caller ID information, with penalties for failure to comply.

What Does This Mean For Your Business?

While individuals have long had the option to silence unknown numbers or install spam blockers, the stakes for businesses are far higher. For example, one missed call might be a scam, whereas another could be a potential client. That’s the balancing act UK firms are now having to perform daily, all while trying to protect staff, safeguard data, and maintain trust with customers. Also, today’s spam calls are often weaponised to breach security systems, manipulate staff, or undermine day-to-day operations.

However, many small and medium-sized enterprises still treat spam call management as a back-office issue. But the evidence suggests it deserves boardroom-level attention. Whether it’s the £1.2 billion in fraud losses reported last year, or the growing number of AI-enabled voice scams, the message is that this is a frontline threat. If left unmanaged, it risks eroding not just productivity, but confidence, both internally and externally.

At the same time, thankfully, telecom providers and regulators like Ofcom are starting to take more decisive steps, from enforcing stricter ID verification rules to proposing new crackdowns on number spoofing. These efforts, while welcome, still rely heavily on businesses taking initiative, by adopting smarter tools, reviewing internal call-handling protocols, and registering with services like the CTPS.

What this all means for UK businesses is a shift in mindset where phone security can no longer really be treated separately from cybersecurity. Stakeholders across departments, from IT and operations to HR and finance, should now collaborate to manage the risks, spot the red flags, and ensure no call gets through that shouldn’t. It’s not just about stopping nuisance calls. It’s about protecting reputation, maintaining customer confidence, and staying one step ahead.

Security Stop-Press: Parking Scam Alert

A rise in parking scams is catching out UK drivers, with criminals using fake fines, phishing texts and QR codes to steal money and personal data.

Cyber security experts report that scammers are leaving fake tickets on windscreens with QR codes linking to fraudulent payment sites. Others are sending texts claiming a fine is owed, often using real location data and links to gov.uk pages to appear legitimate. Victims who pay are unknowingly handing over their personal or financial details.

Bitdefender has identified six of the most common scams — fake windscreen tickets, bogus parking attendants, fake QR codes, phishing texts, fake emails, and fraudulent apps. In some cases, scammers have even posed as attendants in uniform, directing drivers to unauthorised spaces before vanishing with their cash.

The National Cyber Security Centre advises the public to avoid clicking on links in unexpected messages and to check all URLs carefully. Legitimate parking services will not request payment by SMS or through unverified apps. Tools like Scamio can help verify QR codes or suspicious links before any action is taken.

These scams rely on creating a false sense of urgency and trust, making them particularly effective in busy areas such as city centres or event venues.

For businesses, this trend highlights the need to keep employees informed about evolving threats. Promoting secure payment practices, encouraging the use of official apps, and protecting all work devices from phishing and malware can help reduce the risk.

Security Stop-Press: ‘Have I Been Pwned’ Mailing List Stolen in Phishing Attack

Troy Hunt (creator of ‘Have I Been Pwned’) has confirmed his blog’s mailing list was compromised after he fell for a phishing attack mimicking Mailchimp.

Hunt says that while he was jet-lagged in London, he received a convincing phishing email prompting him to log into a fake Mailchimp site, mailchimp-sso.com. Hunt says he entered his login details and a one-time password, only realising the mistake moments later. Despite resetting his password swiftly, the attacker had already exported his mailing list from a New York IP address.

Around 16,000 email addresses were exposed, including over 7,500 belonging to users who had unsubscribed, a detail Hunt criticised, questioning why Mailchimp retains unsubscribed data. The stolen data also included IP addresses and rough location metadata.

Hunt admitted the phishing email was well-crafted, creating just enough urgency without sounding alarmist. “We all have moments of weakness and if the phish times just perfectly with that, well, here we are,” he wrote. Ironically, the incident happened the day after he’d been discussing passkey adoption with the UK’s National Cyber Security Centre.

He has since notified affected users and loaded the breach into Have I Been Pwned, reinforcing his long-held message about transparency and rapid disclosure in data breaches.

For businesses, this incident is a reminder that even experts are vulnerable. Clear phishing awareness training, secure password management, and adoption of phishing-resistant technologies like passkeys are now essential steps in protecting sensitive data.

Security Stop-Press: Cybercriminals Bypassing MFA With Device Code Phishing

Microsoft has reported uncovering a cyberattack campaign by Storm-2372, a group linked to Russian interests, using a technique called device code phishing to bypass multi-factor authentication (MFA) and steal access tokens.

Active since August 2024, the group targets governments, NGOs, and industries including defence, telecoms, energy, and healthcare across Europe, North America, Africa, and the Middle East. In device code phishing, attackers trick users into entering a legitimate authentication code, sent via fake meeting invites on platforms like Microsoft Teams and WhatsApp, on a genuine sign-in page. This hands over valid tokens, granting unauthorised access.

Recent activity shows a shift towards using Microsoft Authentication Broker’s client ID to gain persistent access by registering rogue devices inside compromised networks. Microsoft warns these attacks are especially effective because they mimic legitimate login workflows.

To defend against device code phishing, businesses should block unnecessary device code flows, strengthen Conditional Access policies, educate users about phishing risks, and use phishing-resistant MFA methods such as FIDO tokens.

Security Stop Press: Microsoft Disrupts 240 Phishing Sites Amid Surge in AiTM Attacks

Microsoft’s Digital Crimes Unit (DCU) has reported dismantling 240 fraudulent websites linked to an Egypt-based cybercrime group, thereby disrupting a key operation within the expanding “Phishing-as-a-Service” (PhaaS) industry.

Central to the threat is the rapid rise of “Adversary-in-The-Middle” (AiTM) phishing attacks, which allow attackers to intercept and manipulate communications, bypassing multifactor authentication (MFA) protections. Microsoft’s latest report revealed a 146 per cent surge in AiTM attacks in 2024, as these techniques become the favoured method for breaching secure accounts. The fraudulent ONNX operation, led by Abanoub Nady (“MRxC0DER”), leveraged AiTM tactics alongside “do-it-yourself” phishing kits to execute widespread attacks, heavily targeting the financial sector.

The kits, sold under a fraudulent ONNX brand, enabled criminals to scale their operations, bypassing advanced security measures. Distributed via platforms like Telegram, the kits followed a subscription model with varying levels of support, including step-by-step guidance. Phishing campaigns originating from these kits were among the top five globally by email volume this year, highlighting the threat’s scale and sophistication.

By obtaining a court order to take control of the malicious infrastructure, Microsoft, in partnership with LF Projects, has disrupted the operation, severing access for cybercriminals and sending a strong deterrent message.

Organisations can protect themselves by adopting advanced email filtering, deploying layered MFA solutions, and ensuring regular cybersecurity training. Vigilance and proactive defences remain critical in countering these increasingly sophisticated phishing techniques.