For many organisations, cyber security can feel like something that happens to other people.But for one charity, a seemingly routine email was all it took to put their finances at risk.The charity received an email that appeared genuine and contained a link relating to a payment. With nothing immediately suspicious about the message, a member of staff followed the link and completed the requested payment.Unfortunately, the email was part of a phishing attack.


Phishing is still a major threat
This isn’t an isolated problem.The latest UK Government Cyber Security Breaches Survey 2025/2026 found that 25% of UK charities experienced a phishing attack in the last 12 months.Phishing was by far the most common type of cyber security breach or attack reported by charities. Among charities that experienced a breach or attack, 69% said phishing was the most disruptive type of attack.The figures demonstrate that phishing isn’t simply about the occasional suspicious email landing in an inbox. For organisations, it can represent a genuine financial and operational risk.And attackers don’t need to break through a sophisticated technical defence to cause damage. Sometimes, they just need to convince someone that an email is genuine.It can happen to anyone
The important lesson here isn’t that someone “should have known better”.Modern phishing emails can be remarkably convincing. Attackers deliberately create a sense of familiarity and urgency to encourage people to act before they have time to question what they’re seeing.For charities in particular, limited resources, busy teams and the involvement of staff and volunteers can create additional challenges when it comes to cyber security.A simple pause before clicking can make a big difference.Is the email expected? Is the sender genuine? Does the link go where you would expect? And, most importantly, should this payment really be made?If you’re unsure, verify the request using a separate method of communication rather than relying on the contact details or links within the email.The National Cyber Security Centre recommends that important email requests, particularly those involving payments, are verified using a second form of communication such as a phone call or another trusted method.How can we stop phishing emails hitting our inbox?
Staff awareness is an important part of cyber security, but organisations shouldn’t have to rely on employees spotting every malicious email themselves.The right security technology can help identify and block suspicious emails before they reach an employee’s inbox, reducing the opportunity for someone to click a malicious link, open a harmful attachment or accidentally disclose sensitive information.Effective protection should be about more than email filtering alone.Organisations should take a layered approach to cyber security, combining technology, staff awareness, secure processes and ongoing monitoring.That means making sure systems are kept up to date, vulnerabilities are identified and addressed, ransomware protection is in place and employees know what to do when something doesn’t look right.The goal isn’t to expect people to never make mistakes. It’s to make sure that when a convincing phishing email does get through, there are additional layers of protection in place.

What should you do if you receive a phishing email?
If you receive an email that looks suspicious, don’t click any links, open attachments or respond to the message.Instead:- Check the sender’s email address carefully.
- Be cautious of unexpected payment requests or urgent demands.
- Don’t use links or telephone numbers contained within a suspicious message to verify it.
- Contact the person or organisation through a trusted, separate method if you’re unsure.
- Report the email to your IT support or cyber security provider so it can be investigated and, where appropriate, blocked for other users.
What happens if you do get caught out?
The most important thing is to act quickly and don’t be afraid to report the mistake.If a fraudulent payment has been made, contact your bank immediately and inform your IT support or cyber security provider as soon as possible.The NCSC specifically advises organisations that have been tricked into making a fraudulent payment to contact their bank directly and notify their IT department or IT support as quickly as possible.If you’ve clicked a suspicious link, entered a password or provided sensitive information, tell your IT support team what has happened. They can assess the situation and take appropriate steps to protect your systems and accounts.The sooner an incident is reported, the sooner action can be taken.Can Lansafe help with cyber security?
Yes.Cyber security shouldn’t just begin once something has gone wrong. Having the right protection in place beforehand can help organisations prevent attacks, reduce risk and respond more effectively when threats occur.Lansafe’s IMPACT security offering provides a more comprehensive approach to protecting your organisation’s IT environment.IMPACT can help stop phishing emails from reaching your inbox while strengthening security across your wider IT requirements. The offering includes ransomware protection, patch management and vulnerability management, helping organisations identify and address potential weaknesses before they can be exploited.For organisations that don’t have the resources or specialist expertise to manage every aspect of cyber security internally, having the right support can make a significant difference.Don’t let one click become a major incident
Cyber criminals don’t need a Hollywood-style hack to cause serious damage.Sometimes, all they need is one convincing email, one click and a moment of trust.Take a moment. Check the link. Question the request.It could save your organisation far more than a few seconds.For more information about Lansafe’s IMPACT security offering, contact our team today. We’ll be happy to discuss your organisation’s requirements and explain how IMPACT could help strengthen your cyber security.