05 December 2019
Spear phishing campaigns - they’re sharper than you think
07 August 2017
iOS users beware: You're the biggest target for mobile phishing attacks
20 January 2026
Phishing: Spot and report scam emails, texts, websites and calls
'Phishing' is when criminals use scam emails, text messages or phone calls to trick their victims. The aim is often to make you visit a website, which may download a virus onto your computer, or steal bank details or other personal information.
This page explains how to report phishing attempts, and protect yourself from scammers.
The National Cyber Security Centre (NCSC) is a UK government organisation that has the power to investigate and take down scam email addresses and websites.
reduce the amount of scam communications you receive
make yourself a harder target for scammers
protect others from cyber crime online
Need more help or further advice? Contact Donline.
31 October 2019
Businesses stung by highly convincing Office 365 voicemail scam
25 February 2020
Keep your passwords secure: hackers don't break in, they log in!
16 August 2018
Windows Defender Browser Protection browser extension for Google Chrome
30 April 2026
Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005
Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big breakthrough is an employee clicking "sure, why not" on a fake login page.
The UK government's latest Cyber Security Breaches Survey, released on Thursday, puts the hit rate at 43 percent of businesses and 28 percent of charities reporting a cyber incident in the past year, equating to approximately 612,000 UK businesses and 57,000 UK charities, numbers that have barely budged since the last time it asked.
Most of these breaches do not start with anything especially cutting-edge. Phishing leads "by far," usually via impersonation emails that send staff to fake login pages or get them to click links, open attachments, or hand over sensitive information.
Everything else barely gets a look-in. Around 85 percent of businesses that reported a breach or attack said it involved phishing, leaving malware, ransomware, and unauthorized access trailing some distance behind.
20 April 2018
Microsoft Ports Anti-Phishing Technology to Google Chrome Extension
04 July 2018
Record number of fake HMRC websites deactivated over past year
24 August 2020
Be aware: phone spear phishing attacks are on the rise
27 April 2026
Fake calendar invites are spreading - here’s how to remove them and prevent more
Most of these unwanted calendar entries are there for phishing purposes. Most of them warn you about a “impending payment” but the difference is in the subject and the action they want the target to take. Sometimes they want you to call a number, and sometimes they invite you to an actual meeting.
We haven’t followed up on these scams, but when attackers want you to call them or join a meeting, the end goal is almost always financial. They might use a tech support scam approach and ask you to install a Remote Monitoring and Management tool, sell you an overpriced product, or simply ask for your banking details.
The sources are usually distributed as email attachments or as download links in messaging apps. READ MORE -or- contact DONLINE.
10 May 2018
HMRC urges people to be aware and vigilant of fraudster texts and emails
08 June 2022
Humans are still the weakest link in cybersecurity
According to Proofpoint’s 2022 Human Factor report, 55% of U.S. workers admitted to taking a risky action in 2021. Twenty-six percent clicked an email link that led to a suspicious website, 17% accidentally compromised their credentials and only half were able to correctly identify the term phishing.
“The other part to this equation is that threat actors have gotten a lot better at employing social engineering in their attacks,” said Ryan Kalember, Proofpoint’s executive vice president of cybersecurity strategy. “We see threat actors leverage real life events to solicit an immediate, emotional response, such as with the Ukraine conflict. We also see threat actors employ a combination of email, call centers and live interactions to sell the idea that the communication is legitimate.”
Key to the successful execution of these email-based phishing attacks is trust, the report said. More than ever, hackers today are using stolen credentials to not only gain access to networks and systems but also execute business email compromise and privilege escalation attacks.
25 June 2019
Office 365 Proves Popular with Phishers
07 May 2020
Protecting your organisation against password spray attacks
14 February 2022
What is a SIM swap attack?
SIM swapping is a scam in which malicious parties target cell phone carriers to gain access to victims’ bank accounts, virtual currency accounts and additional sensitive information by using social engineering, insider threat or phishing techniques. Social engineering involves a criminal to impersonate the victim’s mobile number by tricking the cell phone carrier into switching the victim’s mobile number to a SIM card that is in the criminal’s possession, allowing the malicious party to access the victim’s calls, texts and other data, but this is only one of the three methods used to steal funds from victims.
Insider threat takes place when a criminal actor pays off a mobile carrier employee to switch the victim’s SIM to a card currently in the criminal’s possession. Malicious parties can also employ phishing techniques to access victims’ sensitive data, and steal funds from the victim through their banking data or third-party services like PayPal or Venmo. This level of access to a victim’s cell data then allows a malicious party entry to everything from text message verification to SMS based two-factor authentication to exploit victims’ sensitive information.
“Service providers must move from more simplistic means of validating identity to more sophisticated ones,” Clements said. “PIN codes unique to each user’s account can be one way of adding additional security to the process, and ‘out of wallet’ questions are another alternative that works by verifying much harder to compromise information such as last three home addresses or cars. It may be more of a hassle for everyone, but it’s simply no longer viable to rely on information that has been routinely compromised to validate a person’s identity.”
The FBI encourages both cell phone users and the companies that provide service to take additional security measures in protecting their personal information. For cell phone users, the agency outlines the following tips:
Do not advertise information about financial assets, including ownership or investment of cryptocurrency, on social media websites and forums.
Do not provide your mobile number account information over the phone to representatives that request your account password or pin. Verify the call by dialing the customer service line of your mobile carrier.
Avoid posting personal information online, such as mobile phone number, address or other personal identifying information.
Use a variation of unique passwords to access online accounts.
Be aware of any changes in SMS-based connectivity.
Use strong multi-factor authentication methods such as biometrics, physical security tokens, or standalone authentication applications to access online accounts.
Do not store passwords, usernames or other information for easy login on mobile device applications.
14 December 2018
Iranian phishers bypass 2fa protections offered by Yahoo Mail and Gmail
18 April 2017
Phishing with Unicode Domains - scary stuff!
23 August 2019
How to avoid ransomware attacks: 10 tips
- Keep clear inventories of all of your digital assets and their locations, so cyber criminals do not attack a system you are unaware of.
- Keep all software up to date, including operating systems and applications.
- Back up all information every day, including information on employee devices, so you can restore encrypted data if attacked.
- Back up all information to a secure, offsite location.
- Segment your network: Don't place all data on one file share accessed by everyone in the company.
- Train staff on cyber security practices, emphasizing not opening attachments or links from unknown sources.
- Develop a communication strategy to inform employees if a virus reaches the company network.
- Before an attack happens, work with your board to determine if your company will plan to pay a ransom or launch an investigation.
- Perform a threat analysis in communication with vendors to go over the cyber security throughout the lifecycle of a particular device or application.
- Instruct information security teams to perform penetration testing to find any vulnerabilities.
24 August 2022
7 cybersecurity terms every hybrid employee should know
An employee working from home opens an attachment in an existing email thread with coworkers. Someone else quickly types in a URL to look something up while working on a project, without noticing they made a small typo. A new colleague receives an email that looks like it comes from a payroll company and responds with their Social Security number and bank account information.
Each of these scenarios could be just part of a normal day for an employee who spends most of their time working at a computer. But they’re also opportunities for a cyber attack that could wreak havoc for an entire company, its employees, and its customers. Now that more employees are working remotely for all or part of the work week, outside of the security of a company’s internal IT systems, the threat is even greater. In the first few months of the pandemic, cyber attacks on cloud infrastructure skyrocketed by 600%.
“Employees have a role to play, but more sophisticated attacks make it next-to-impossible to spot them,” says Ian Pratt, global head of security for Personal Systems at HP. “That’s why it’s key that employees feel empowered to inform IT when something looks off.”
1. Ransomware
2. Spear phishing
3. Spoofing
4. Pretexting
5. Typosquatting
6. Shoulder surfing
7. Zero-click attack
Click here to find out more & protect yourself & your business.












