Types of phishing attacks that could cost Businesses over £100M
Learn about the types of phishing attacks targeting businesses and employees, including workplace scams, warning signs and modern phishing methods.
Ransomware is a type of malware that infects computers and encrypts or locks files, preventing employees from accessing important data. Cybercriminals then demand money in exchange for unlocking or restoring access to the data.
The ransom demanded can sometimes reach seven or eight figures, making ransomware attacks extremely costly. Even after a payment is made, there is no guarantee that the data will be recovered. Cybercriminals may also steal sensitive information, such as customer data, and publish or sell it on the dark web, allowing others to misuse the information as well.
The first known ransomware attack occurred in 1989 and involved malware called the AIDS Trojan, also known as PC Cyborg. It was created by Joseph Popp, a biologist who distributed around 20,000 infected floppy disks to people connected with an international AIDS conference and other mailing lists. The disks appeared to contain useful AIDS-related information, but after being installed, the malware eventually hid or locked access to files and demanded a payment of US$189 to PC Cyborg Corporation.
The attack is widely regarded as the first documented ransomware attack and introduced the basic idea that modern ransomware still uses today: restricting access to a victim's data and demanding money to restore it. Popp was later arrested and charged with blackmail, although he was ultimately found mentally unfit to stand trial.
A ransomware attack typically moves through a series of stages before a victim ever sees a ransom demand.
The main ways of a ransomware attack are phishing, vulnerability exploitation, and compromising remote access protocols like RDP.
The most used method for attackers carrying out ransomware attacks is phishing, and the most common vulnerability is human vulnerability: an employee who ignores the red flags of an email and clicks on an attachment file.
Although your staff may have completed cybersecurity training before, they may still be targeted due to the more convincing methods attackers use and also their access to AI to write convincing texts or use voice agents.
Scrambles and encrypts files like documents, videos, and photos.
Your computer still runs, but your data is completely inaccessible without the decryption key.
It hit the UK's National Health Service (NHS), scrambling patient data, shutting down hospital computers, and forcing the cancellation of roughly 19,000 medical appointments.
This attack infected over 200,000 computers globally across 150 countries. It automatically scanned networks for a specific Windows security vulnerability (EternalBlue) to encrypt device files.

Locks you completely out of your operating system user interface.
You cannot access your desktop or apps; only a full-screen ransom note appears.
Unlike crypto ransomware that leaves the operating system running, Petya immediately forced a computer reboot. It then overwrote the Master Boot Record (MBR), completely blocking the Windows operating system from loading.
Users turned on their computers only to find a red screen with a full-screen skull icon and a demanding ransom message, with zero access to any applications.
Steals sensitive personal or corporate data instead of, or in addition to, encrypting it.
Threatens to publish trade secrets, customer records, or private photos online if you refuse to pay.
The Cl0p gang bypassed encryption entirely for thousands of victims. Instead, they exploited a vulnerability in the widely used MOVEit file-transfer software to steal mass amounts of sensitive data.
Cl0p listed hundreds of major corporations and government agencies on their "name-and-shame" leak site. They extorted the entities solely on the threat of making those stolen documents completely public.
Mimics official security software or police alerts via pop-ups claiming your PC is infected or compromised.
Panics users into purchasing fake cleanup tools or paying bogus "fines" to unlock their browser.
Users browsing malicious sites are hit with aggressive, un-closable browser pop-up windows that flash warning lights and sound simulated sirens.
The pop-ups alert the user that dozens of viruses have been found on their device. The user is tricked into paying for a useless "premium security tool" to clean the fake infection.
Targets smartphones and tablets, usually via malicious third-party app downloads.
Blocks user access to the mobile screen, steals contact logs, or encrypts device storage.
Primarily spread via untrusted third-party app stores or adult websites, this malware targets mobile operating systems.
Once installed, it takes over the Android layout, rendering the home button, back button, and power options useless. It demands a payment, often via Apple Gift Cards or cryptocurrency, to give the phone back to the owner.
A subscription business model where professional developers lease ransomware variants to low-skilled hackers, known as affiliates.
Massively scales the volume of global attacks, with profits split between the developers and attackers.
Qilin operates as a massive franchise, renting its encryption tools to independent criminal affiliates in exchange for a cut of the profits.
Qilin was responsible for a major attack on London pathology provider Synnovis, which severely disrupted blood testing across several NHS hospitals.
One of the most common methods attackers use to carry out a ransomware attack is phishing. In many cases, the biggest vulnerability is human error, such as an employee ignoring warning signs in an email and clicking on a malicious attachment or link.
Even if your staff have completed cybersecurity training, they may still be targeted because attackers are using increasingly convincing techniques. With access to AI, cybercriminals can create more realistic emails, messages, and even voice interactions, making phishing attempts harder to identify.
A phishing campaign is an organised attempt to trick people into revealing sensitive information or taking an unsafe action.
Attackers may send fake emails, text messages, or login pages that appear to come from a trusted company, manager, bank, or supplier. Their goal is often to steal passwords, financial details, or access to business systems.
It is called a campaign because it is a planned series of phishing attempts, not usually just one message.
Attackers may send hundreds or thousands of similar emails over several days, targeting a particular company or group. The messages often share the same goal, such as stealing passwords, spreading ransomware, or tricking employees into making payments using different types of phishing; similar to how a marketing campaign uses coordinated messages to achieve one objective.
Receiving a ransomware email does not always mean the company has been successfully attacked. Treat it as a serious incident until checks show otherwise.

The NCSC recommends rapid containment, investigation and structured recovery during ransomware attack.
If someone already clicked or opened the attachment, they should immediately stop using the device, disconnect it from Wi-Fi and network cables, and contact IT. The business should isolate affected systems, activate its incident-response plan, preserve evidence, check backups, and assess whether data was accessed or encrypted.
A director or senior manager should temporarily take ownership and appoint:
The business can then use this simple temporary reporting route:
For a UK business, charity or organisation experiencing a live cyberattack, call Report Fraud on 0300 123 2040 immediately. The live cyberattack service operates 24 hours a day. Reports can also be submitted through the Report Fraud website. In Scotland, criminal reports may also need to go to Police Scotland.
Use the NCSC Report a Cyber Incident service. The NCSC can receive technical incident information and may provide guidance or coordinate support, particularly for significant incidents.
Ransomware can be a personal-data breach even when data was only encrypted and not proven stolen, because the company may have lost access to personal information.
The company must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach when it is likely to create a risk to individuals' rights and freedoms. The company should notify affected people without undue delay where the risk to them is high. All personal-data breaches and the reasoning behind reporting or not reporting must be documented.
An initial ICO report can be made before every fact is known and supplemented later. It should include, as far as known:
Depending on the business, it may also need to inform:
The NCSC and UK law enforcement do not encourage ransom payments. Payment does not guarantee recovery, deletion of stolen data, or protection from another demand.
https://www.reportfraud.police.uk/ransomware
A payment can also be unlawful if money or economic resources are provided to a sanctioned person or organisation. No payment or negotiation should happen without specialist legal advice, insurer involvement and sanctions checks.
National Cyber Security Centre: ransomware attack response, recovery guidance and incident reporting.
https://www.ncsc.gov.uk/section/advice-guidance/all-topics/ransomware
Report Fraud: police reporting for fraud and cybercrime, including the 24-hour live business attack number.
https://www.reportfraud.police.uk/reporting-a-fraud/
Information Commissioner's Office: ICO breach assessment, reporting and 72-hour guidance.
Business.gov.uk: a practical business cyberattack response guide and links to assured incident-response professionals.
GOV.UK Cyber Security Guidance for Business: government guidance, Cyber Essentials support, Cyber Resilience Centres and approved advisers.
https://www.gov.uk/government/collections/cyber-security-guidance-for-business
OFSI ransomware sanctions guidance: important before considering or facilitating any payment.
Optimise Cyber Solutions helps with preparation, staff response skills, ransomware attack exercises, awareness training and developing an incident-reporting process. Optimise was founded by the former UK national cyber incident-response lead and provides practical, scenario-based cyber training aligned with NCSC guidance.
Optimise Cyber can help you coordinate the initial response, understand your reporting obligations and strengthen your incident process. Where specialist live forensics or recovery is required, we will confirm the appropriate technical response route.
Learn about the types of phishing attacks targeting businesses and employees, including workplace scams, warning signs and modern phishing methods.
Is Microsoft Teams secure for confidential information? Learn how phishing, fake IT support, malicious links and role-based scams can put business data at risk.
Discover how the TfL cyber attack exposed human vulnerabilities and why cyber security training for businesses is essential for reducing risk.