Skip to main content
Inflection Point
Cyber Security 23 May 2025 3 min read Verified 5 May 2026

Phishing Clicks Have Tripled: How To Protect Your Business

I

Iain Godding

Owner / Founder / Managing Director

Phishing Clicks Have Tripled: How To Protect Your Business

Phishing Scams Are Evolving: Is Your Business Prepared? Imagine this: your team is working hard, navigating the web, and handling daily tasks. But behind the scenes, cybercriminals are becoming more clever, and phishing scams are getting harder to spot. The number of employees clicking on phishing l

Phishing Scams Are Evolving: Is Your Business Prepared?

Imagine this: your team is working hard, navigating the web, and handling daily tasks. But behind the scenes, cybercriminals are becoming more clever, and phishing scams are getting harder to spot.

The number of employees clicking on phishing links has tripled over the last year.

Businesses everywhere are paying the price. This isn't just a financial issue; it can lead to data breaches, reputational damage, and loss of customer trust.

"Enterprise phishing click rates tripled in 2024 compared to the previous year"
Source: Netskope Threat Labs Cloud and Threat Report (January 2025)

Analysis of enterprise phishing trends showing dramatic increase in successful phishing attacks.

"85% of all UK business breaches are caused by phishing attacks"
Source: UK Cyber Security Breaches Survey 2025 (2025)

Making phishing the single most common attack vector facing UK organisations.

"94% of organisations faced phishing attacks in 2024"
Source: Proofpoint State of the Phish (2024)

Near-universal exposure to phishing threats across all business sizes.

What is Phishing and Why Should Your Business Be Concerned?

Phishing is when scammers impersonate a trusted source, like Microsoft or a bank, to steal sensitive information such as passwords, payment details, or access to business systems.

For example, one of your employees might receive an email that appears to be from Microsoft 365, asking them to click on a link and enter their login details. Once they do, that information goes straight to the criminals, giving them access to your business.

Here's the real problem, these attacks are becoming more sophisticated. While email phishing remains a big threat, scammers are also using fake links in search engines, social media, online ads, and even website comments. They know your employees are cautious about suspicious emails, so they are now trying to trick them on other platforms.

Why Are More Businesses Falling for These Scams?

The rise in phishing attempts and the increasing sophistication of these attacks can lead to fatigue among employees. They're bombarded with scam emails every day, making it difficult to stay vigilant. Phishing emails and fake websites now look nearly identical to legitimate ones, so it's easy for well-intentioned employees to fall for scams.

Popular platforms like Microsoft, which store valuable business data, are prime targets for scammers. If attackers gain access to these systems, they could cause devastating breaches for your business.

The reality is your team can be your greatest defense or your biggest vulnerability. A well-trained and alert team can spot phishing attempts before any damage is done. But if your employees aren't prepared, a single click can lead to stolen data, financial losses, and lasting damage to your business's reputation.

How Can Your Business Protect Itself from Phishing Scams?

The good news is that there are proactive steps your business can take to protect itself. Here's how:

  1. Employee Education: Regular training is essential. Ensure your team knows how to spot phishing attempts, not just in emails but across the web. Teach them to recognise suspicious requests for login details, fake links, and other signs of phishing.
  2. Implement Multi-Factor Authentication (MFA): Adding an extra layer of security helps protect your business. Even if a password is compromised, MFA ensures attackers can’t easily access your business systems.
  3. Keep Software Updated: Outdated software is an easy target for cybercriminals. Make sure your systems, especially those used to access sensitive business data, are always running the latest security patches.
  4. Establish Strong Cybersecurity Protocols: A solid cybersecurity strategy is crucial in preventing phishing attempts from succeeding. This should include firewalls, email filters, anti-phishing software, and continuous monitoring.

It’s Time to Take Action

Phishing scams aren't going away, but with the right approach, your business can avoid falling victim. By educating your team, implementing stronger security measures, and staying vigilant, you can reduce the risk significantly.

If you're concerned about phishing or need help strengthening your business's cybersecurity, we're here to help. Get in touch with us today, and let us assist in protecting your business and its data.

Frequently Asked Questions

Why have phishing clicks tripled?

Attackers are using more sophisticated techniques, including AI-generated content that mimics legitimate communications more convincingly. Cloud-based collaboration tools have also expanded the attack surface beyond traditional email.

How can I tell if an email is a phishing attempt?

Look for urgent language demanding immediate action, unexpected attachments, sender addresses that don't match the organisation they claim to represent, and links that go to unfamiliar domains. When in doubt, contact the sender through a known, trusted channel.

What should I do if an employee clicks a phishing link?

Immediately isolate the affected device from the network, reset the user's passwords, scan for malware, and report the incident to your IT provider. Time is critical—the faster you respond, the less damage can occur.

Does security awareness training actually work?

Yes. Organisations with regular security training reduce phishing susceptibility by up to 75%. The key is consistent, ongoing training rather than one-off sessions—threats evolve, and so should your team's awareness.

How often should we run phishing simulations?

Monthly phishing simulations are recommended, with immediate feedback for those who click. This creates a culture of vigilance without shaming employees, turning security awareness into a habit rather than an afterthought.

Sources

  1. Netskope Threat Labs. Cloud and Threat Report . (2025)
  2. UK Government. Cyber Security Breaches Survey 2025 . (2025)
  3. Proofpoint. State of the Phish Report . (2024)
  4. World Economic Forum. Global Cybersecurity Outlook 2025 . (2025)
  5. IBM. Cost of a Data Breach Report . (2024)

Written by

Iain Godding

Owner / Founder / Managing Director

Iain has over 25 years’ experience delivering large-scale technology programmes across public and private sectors. As our MD he brings this enterprise-grade IT expertise to SMEs in the South West in a way that’s accessible, scalable, and commercially valuable. A champion of innovation, he’s at the forefront of applying AI and automation to help clients streamline operations, improve decision-making, and unlock new value. Iain has built a culture that prioritises innovation, service excellence, and long-term client partnerships, helping businesses of all sizes achieve more with technology. Outside work, Iain advises growing businesses as a board member and non-executive director.

View all posts by Iain
Get Expert Help

Ready to transform your IT?

Our team of experts is here to help you navigate technology decisions and find solutions that drive real business value.