Phishing in 2026: The New Tricks Targeting Small Teams
AI-generated voices, fake invoices, and QR-code scams are getting past old training. Here's what modern phishing looks like and how to train your team against it.

The advice most people absorbed about phishing — look for bad spelling, check for a generic greeting, hover over the link — was written for a era of attack that has largely passed. Today's attempts are well written, personalised, and often reference real details about your business.
Here is what has actually changed, and what to teach instead.
The message that knows things about you
Attackers research targets now. A convincing message might reference a project you are genuinely working on, a supplier you genuinely use, or a colleague who is genuinely travelling this week. Much of that is public — your website, social media, a conference listing.
This breaks the old advice completely. A message can be specific, accurate, and correctly addressed and still be an attack.
Voice that sounds like someone you know
Voice synthesis has reached the point where a short sample — a video, a voicemail greeting, a recorded talk — is enough to produce convincing audio. The typical use is a brief, urgent call from someone senior asking for a payment or a credential, usually with a reason it cannot wait.
The defence is procedural rather than perceptual. You cannot reliably tell by listening, so do not try:
- Any request to move money or change payment details gets verified on a number you already had, never one supplied in the request
- Agree in advance that nobody senior will ever be annoyed about being called back to confirm
- Treat urgency itself as the warning sign, because manufactured time pressure is the one constant across these attempts
Invoice and payment redirection
The most costly attacks on small businesses are often the least dramatic. A supplier emails to say their bank details have changed. The invoice looks right because it is a copy of a real one. The amount is unremarkable. Nobody questions it until the real supplier asks why they have not been paid.
QR codes
A QR code hides its destination until you have already opened it, usually on a phone, where the address bar is truncated and there is no easy way to inspect anything. Codes turn up in emails, on parking meters, on printed notices, and on stickers placed over legitimate codes.
Treat a scanned code exactly as you would a link in an email from a stranger, and never enter credentials on a page you arrived at by scanning something.
What to train instead
Stop teaching people to spot fakes — attackers have got too good at not looking fake. Teach process instead, because process holds regardless of how convincing the message is:
- Verify out of band. Anything involving money, credentials, or access gets confirmed through a channel you chose, not the one that contacted you.
- Urgency triggers the check. Pressure to act immediately is the reason to slow down, not the reason to hurry.
- Make reporting effortless and blameless. People who fear looking foolish stay quiet, and silence is what turns a click into a breach.
- Turn on multi-factor authentication everywhere. It is what limits the damage when someone eventually does hand over a password.
Assume someone will click eventually — that is a realistic expectation, not a pessimistic one. Build so that a single mistake is recoverable. If you want help putting those controls in place, get in touch.
More from the blog


