The phishing email that arrives today doesn't look like the ones from five years ago. It doesn't have spelling mistakes. It doesn't ask you to click a suspicious link to claim a prize. It's written in fluent, professional English. It references your company by name, mentions a supplier you actually use, and asks you to approve an invoice that looks entirely legitimate. And it's been generated, personalised and sent at scale using artificial intelligence.
This is the new normal for UK businesses in 2026, and the results are alarming. The National Cyber Security Centre's latest threat report identified AI-enhanced phishing as the fastest-growing attack vector targeting SMEs in the UK — and businesses that lack proper security controls are being compromised at rates that would have seemed extraordinary just three years ago.
What Has AI Actually Changed?
The core mechanics of phishing haven't changed — a criminal sends a deceptive message to trick someone into taking a harmful action, whether that's clicking a malicious link, handing over credentials, or authorising a payment. What AI has changed is the quality and scale at which these attacks can be executed.
Previously, a targeted phishing attack — known as spear phishing — required significant human effort. An attacker had to research their target, craft a believable message, and send it manually. That limited the number of businesses they could target at once.
Now, AI tools can scrape your company's website, your LinkedIn profile, your Companies House filing, and your social media in seconds. They can identify your suppliers, your clients, your job titles, and your communication style. They can then generate hundreds of uniquely personalised, contextually accurate phishing emails and deploy them automatically. What used to take a skilled attacker several hours per target now takes a few seconds per target at industrial scale.
Real example: A professional services firm in Leicester received an email that appeared to come from their accountant, referencing a specific invoice number and asking the finance manager to update banking details ahead of a payment run. The email was grammatically perfect, used the correct names, and the domain was a single-character variation of the real one. The attack was caught — but only because the firm had email security filtering in place that flagged the domain discrepancy. Without it, the payment would have gone through.
The Rise of Deepfake Voice and Video Attacks
Phishing emails are the most common AI-powered attack, but they're not the only one. A growing number of UK businesses are encountering voice phishing (vishing) attacks that use AI-generated audio to impersonate senior colleagues, suppliers or bank representatives with startling accuracy.
In one well-documented case, a UK firm's finance director received a voice call that appeared to be from the CEO, instructing them to make an urgent transfer. The voice was synthesised from publicly available audio of the real CEO speaking at a company event. The transfer was made before anyone thought to verify through a separate channel.
This isn't science fiction. The technology required to clone a voice from as little as three seconds of audio is freely available, and the attacks are increasing in frequency. Businesses that have public-facing executives — founders who appear in promotional videos, directors who speak at events — are particularly exposed.
Why SMEs Are the Primary Target
It's tempting to think that sophisticated cyberattacks are aimed at large corporations with valuable data and deep pockets. In reality, SMEs are often the primary target, for several reasons.
First, they're less defended. Large enterprises have dedicated security teams, advanced tooling, and formal security protocols. Most SMEs have neither the budget nor the in-house expertise to match that. Second, SMEs are often part of supply chains that include larger, more valuable targets — attacking a small supplier is a way in through the back door. Third, cyber criminals know that SME employees are less likely to have received formal security training, making social engineering attacks more likely to succeed.
We support businesses across Derby, Nottingham and Leicester, and the pattern we see is consistent: the businesses most at risk are those that haven't updated their security posture since their early years, assume that basic antivirus is sufficient, and have never run a simulated phishing exercise to test their staff's awareness.
What Does Proper Protection Look Like?
The good news is that effective protection against AI-powered phishing doesn't require a security team or an enterprise budget. It requires the right controls, properly configured and actively maintained. The key layers are:
Email Security Filtering
A dedicated email security solution — not just the built-in Microsoft 365 junk filter — analyses incoming emails for malicious content, suspicious domains, impersonation attempts and known threat patterns. Modern email security platforms update their threat intelligence continuously, which means newly identified phishing campaigns are blocked before they reach inboxes. This is the single most effective layer of protection against phishing.
Multi-Factor Authentication Everywhere
Even if an attacker successfully steals a set of credentials through phishing, MFA prevents them from using those credentials to access your systems. Every account — Microsoft 365, line-of-business applications, remote access — should require a second factor. Without MFA, one successful phish can result in a full account takeover.
Endpoint Detection and Response (EDR)
EDR software does far more than traditional antivirus. It monitors device behaviour in real time, identifying suspicious activity — malicious processes, unusual file access, lateral movement — that signature-based antivirus would miss. If a phishing link does get clicked and delivers a payload, EDR is your last line of defence.
Staff Awareness Training and Simulation
Technology controls are essential, but humans remain the most targeted entry point. Regular, scenario-based security awareness training — combined with simulated phishing exercises that test your staff's real-world response — dramatically reduces the likelihood of a successful attack. Staff who've seen a convincing fake are far better equipped to spot a real one.
The verification rule: Regardless of what security controls you have in place, instil one simple rule across your organisation: any request to make a payment, change banking details, or grant system access should always be verified through a separate channel before being actioned. A phone call to the person on their known number. A message on Teams. Never just reply to the email. This one rule has prevented more successful attacks than almost any technical control.
Business Email Compromise: The Financial Attack to Watch
Closely related to phishing, business email compromise (BEC) is one of the most financially damaging cyber threats facing UK SMEs today. In a BEC attack, criminals either gain access to a legitimate email account or spoof one convincingly enough to fool the recipient, then use it to redirect payments or authorise fraudulent transactions.
The FBI's Internet Crime Complaint Center reported global BEC losses exceeding $2.9 billion in its most recent annual report. In the UK, the National Fraud Intelligence Bureau recorded a significant year-on-year increase in BEC incidents targeting SMEs throughout 2025. These aren't attacks on large banks or government departments — they're attacks on the accounts payable teams of small businesses exactly like yours.
What to Do This Week
If you're reading this and you're not confident about the security posture of your business, there are three things worth doing immediately:
- Check whether MFA is enforced on every Microsoft 365 account in your organisation. Go to the Microsoft 365 admin centre and check your authentication policies. If conditional access isn't configured, you have a significant gap.
- Send a test phishing email to yourself from a free tool like GoPhish and see whether your email security catches it. If it lands in your inbox, your current filtering isn't sufficient.
- Talk to your IT provider about what email security solution is in place and when it was last reviewed. If they can't answer clearly, that's a problem in itself.
AI has made the threat landscape harder to navigate, but it hasn't made protection impossible. The businesses that stay safe are the ones that take security seriously as an ongoing discipline — not something to address after an incident.