All systems operational · Ormskirk, North West England

Employees Are Falling for Three Times More Phishing Scams

Employees are falling for phishing scams at three times the rate of last year. Attacks have expanded beyond email and grown harder to spot. Here is why existing training may no longer be enough.

The Scale of the Problem

The rate at which employees are falling for phishing scams has tripled compared to the previous year. That is not simply because phishing is more common, although it is. It is because the attacks have become harder to distinguish from genuine communications, and they now appear across far more channels than before.

Phishing is the practice of impersonating a trusted source to steal passwords, payment details, or access to systems. Where it once arrived almost exclusively by email, it now operates through search engine results, social media, online adverts, and website comments. The scope of what your team needs to watch for has expanded considerably.

Why Staff Are Getting Caught Out

Alert fatigue

Staff who see suspicious emails daily can become desensitised to the warnings. When every other message triggers a security prompt, genuine threats start to blend into the background noise. Employees begin filtering instinctively rather than checking carefully, and that is where mistakes happen.

More convincing attacks

Phishing emails and pages now closely replicate the genuine article. Attackers research their targets, use correct branding, match writing styles, and reference real projects or colleagues. The casual glance that used to be enough to spot a fake is no longer reliable.

Training that has not kept pace

Much cyber security awareness training still focuses on email-based phishing. But staff also need to be able to identify suspicious links in search results, fake social media messages, and fraudulent adverts. Training that covers only one channel leaves gaps elsewhere.

What to Do About It

Training needs to cover all the channels phishing now uses, not just email. Practical simulations that expose staff to realistic fake attempts in a safe environment are more effective than briefings. Regular short sessions maintain awareness better than an annual one-off.

Multi-factor authentication provides a critical backstop. Even if an employee enters their credentials on a phishing page, MFA prevents the attacker from using those credentials to log in without the second factor. It does not eliminate the problem but it substantially limits the damage when someone is caught out.

Blowfish Technology supports businesses across the North West with cyber security awareness programmes and managed security, including IT Support Lancashire, IT Support Wirral, and IT Support Cheshire.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.