Menu Close

Phishing in 2026: how to spot it and protect your business

Introduction

If you run a professional practice — whether you’re an accountant, a doctor, a law firm, or an administrative office — phishing is one of the most real cybersecurity threats you face today. It’s not just a problem for large corporations: cybercriminals actively target professionals and small businesses, which are often less protected yet hold highly sensitive data.

In this article, I’ll explain what phishing is, how it has evolved in 2026, and — most importantly — what you can do right now to protect yourself. No technical jargon, just practical advice, real examples, and immediately applicable information.

What is phishing?

The term phishing plays on the word ‘fishing’: criminals cast a bait — usually an email, a message, or a fake webpage — and wait for the victim to take it.

The goal can vary:

  • stealing login credentials (email, management software, online banking)
  • installing malware or ransomware on your computer
  • tricking you into a bank transfer to a fraudulent account
  • obtaining personal or business data to sell on the dark web

How phishing has changed in 2026

A few years ago, phishing emails were often easy to spot: poor grammar, pixelated logos, obviously fake senders. Today, the picture is very different.

Thanks to generative AI, fraudsters can now produce perfectly written messages, personalised with your name, your firm’s name, or even the name of one of your real suppliers. This is called spear phishing: not a generic message sent to millions, but a scam built specifically for you.

The most widespread techniques in 2026 include:

  • Emails that perfectly mimic official communications from tax authorities, banks, or couriers
  • WhatsApp messages from unknown numbers with links to fake login pages
  • Phone calls from fake operators asking you to ‘verify your access’ to a portal
  • Physical QR codes (on flyers, packages, notices) that lead to fraudulent websites
  • Fake invoices sent from email addresses very similar to those of real suppliers

💡  In 2026, the golden rule is: never trust a message based on appearance alone. An email can look perfect and still be a scam.

Three real-world phishing email examples

Spotting phishing takes a trained eye. Here are three typical examples — reconstructed from cases we regularly see in our clients’ inboxes — with the signals that give them away.

⚠  Example 1 — Fake tax authority notice
From: HMRC Notifications <[email protected]>
Subject: Urgent notice: tax irregularity ref. 2026/HMRC-08471

Dear taxpayer, automated checks have detected an irregularity in your latest return. To prevent the start of an assessment procedure, you must verify your details within 24 hours of receiving this email.
Access the dedicated portal: https://hmrc-secure-verify.com/login Kind regards, HMRC Notifications Office

Suspicious signals: The real HMRC domain is hmrc.gov.uk, not ‘hmrc-online-services.co’.Artificial urgency: ‘within 24 hours’ to push you to act without thinking.Link to a suspicious domain with reassuring words like ‘secure-verify’.Impersonal tone: tax authorities communicate via official mail and registered channels, not generic emails.
⚠  Example 2 — Fake supplier invoice (IBAN swap / CEO fraud)
From: Mark Brown <[email protected]>
Subject: RE: Invoice no. 0247/2026 — updated bank details

Hi, I’m forwarding the updated invoice. Just a heads up: our bank has changed.

Please make the transfer to the new IBAN GB60 BARC 2010 3212 3456 78 in the name of Supplier Ltd. Reissued invoice attached.
Thanks,
Mark
Suspicious signals: In the domain ‘suppIier-ltd.com’ the lowercase ‘l’ is actually a capital ‘I’ — visually identical.A bank-details change announced via email should always be verified by phone, using a number you already have.Friendly tone that mimics an existing relationship to lower your guard.Attached ‘reissued invoice’ may contain PDFs with malicious links or macros.
⚠  Example 3 — Fake Microsoft 365 mailbox warning
From: Microsoft 365 Support <[email protected]>
Subject: Your mailbox is full — action required

Hello [email protected], we have detected that your mailbox has reached 98% of its capacity. Incoming emails may not be delivered.

Click here to free up space and keep your account active: [Free up space now] Microsoft 365 — Security Team

Suspicious signals: Sender is not on the official microsoft.com domain: ‘ms365-notice.app’ is not a Microsoft channel.Vague technical alert (‘mailbox at 98%’) designed to trigger an immediate click.The button redirects to a fake Microsoft login page that harvests username and password.Microsoft never asks you to ‘free up space’ through email links; the real message appears in the admin portal.

Warning signs to watch for

Even the most sophisticated phishing campaigns leave traces. Here’s what to look out for:

  • The sender’s email address: check the full domain, not just the display name. An address like ‘[email protected]’ is not HMRC.
  • Artificial urgency: messages pushing you to act ‘within 24 hours’ or ‘immediately’ to avoid a serious consequence.
  • Suspicious links: hover over the link (without clicking) and check the real URL shown at the bottom of your browser.
  • Unusual requests: no bank or public authority will ever ask for your password, PIN, or OTP codes via email.
  • Unexpected attachments: a PDF or .zip file you weren’t expecting is a red flag, even if the sender looks familiar.
  • Subtle inconsistencies: even in well-written emails, look for mismatches in logo, tone, or content compared to official communications.

What to do if you receive a suspicious email

If you have doubts about a message:

  • Do not click any links and do not open attachments.
  • Do not reply to the message, not even to ask for confirmation.
  • If the message pretends to come from your bank, a supplier, or an authority, contact that entity directly through official channels (phone, official website).
  • Report the message as phishing to your email provider (Gmail, Outlook and others have this feature).
  • If you work in a practice with colleagues, alert your IT manager or consultant.

💡  Have you already clicked a suspicious link? Disconnect your computer from the network, do not enter any credentials, and contact me immediately — fast action makes all the difference.

5 practical steps to protect your practice

You don’t need to be an IT expert to significantly reduce risk. Here are the essentials:

  • Two-factor authentication (2FA): enable it on every email account and portal that supports it. Even if someone steals your password, they can’t log in without the second code.
  • Unique, complex passwords: use a password manager (Bitwarden, 1Password) to generate and store different passwords for each service.
  • Software updates: keep your OS, browser and antivirus up to date. Many attacks exploit outdated software.
  • Staff training: the human factor is the most exploited weakness. A short, regular briefing on how to spot scams can prevent costly incidents.
  • Regular data backups: a recent backup, separated from the network, lets you recover quickly even after a ransomware attack.

The role of the IT consultant in prevention

Tackling cybersecurity on your own while running a professional practice isn’t easy. A trusted IT consultant can:

  • set up email filters to intercept malicious messages before they reach your inbox;
  • define security policies suited to your specific setup;
  • train your staff in a practical, hands-on way;
  • intervene quickly in case of an incident.

For over 15 years I have supported professional practices and small businesses in Tuscany and across Italy in managing their IT infrastructure. If you want to assess your practice’s security level or have doubts about a suspicious message, get in touch for a no-obligation consultation.

Conclusions

Phishing in 2026 has become more sophisticated, personalised, and harder to spot. But with the right habits and tools, you can drastically reduce the risk of falling for a scam.

Remember: the best defence is awareness. Slow down, look carefully, and when in doubt, verify before you click.

Got questions about your practice’s cybersecurity? Write or call me — I’m here to help.