A convincing phishing message can reach a finance manager in one country while the colleague expected to verify it is asleep in another. The most effective defence is to recognise the tactics, then make payment and account changes impossible to approve on a message alone.
Cybersecurity threats such as email phishing aren’t unique to international organisations, and cross-border teams aren’t inherently at greater risk. However, social engineering can exploit gaps in checking requests across time zones, languages and working hours. Cyber criminals may also use domain spoofing to make a request look legitimate, so clear verification and reporting rules help close those gaps.
Key takeaways
- A phishing attack may seek money, account access or company information, arriving by email, text, phone or malicious file.
- Treat unexpected requests to change bank details, share credentials or act urgently as unverified until confirmed through a known, separate channel.
- Give every office a clear way to report suspicious messages, including outside UK working hours.
- If someone clicks, shares details or opens a suspicious file, contact IT promptly. Fast containment can limit further access.
Payment and authority phishing tactics
International payment flows and seniority-based approval processes can give fraudulent requests a plausible context. Messages may look ordinary, so employees need a verification process that works across locations.
1. Business email compromise and payment diversion
Cyber criminals may impersonate a trusted contact or gain access to their account, then request a payment or a change to supplier bank details. The request may arrive during an invoice cycle, appear to continue an existing conversation, or claim that a transfer must be completed before a deadline.
For a company paying suppliers across borders, a changed account number can be harder to query when contacts are in different time zones. Require staff to verify new or amended payment instructions using a known phone number, not the contact details in the message. The NCSC’s business payment fraud guidance sets out what to do if a business receives a fraudulent payment request.
2. Executive impersonation, or whaling
Whaling targets senior staff, while executive impersonation uses a leader’s name or role to pressure someone into acting. This targeted approach can be spear phishing: a message might ask a finance employee to make an urgent transfer or request sensitive information before a confidential announcement. Artificial intelligence may make a message more convincing, but it doesn’t replace verification.
The sender’s title doesn’t replace normal approval. Require a second authorised person for high-value payments, and confirm unusual requests through a known channel. Publish the same rule to every office so staff aren’t left to decide whether a senior person’s instruction overrides local procedure.
Phishing tactics that steal account access
A message can be designed to look routine rather than alarming. These approaches aim to collect credentials or make a forged email seem trustworthy.
3. Spoofed or lookalike sender domains
Domain spoofing makes an email appear to come from a trusted domain, while a lookalike domain uses a subtly altered address to imitate a supplier or colleague. Cyber criminals may use either approach in a targeted spear phishing message. A swapped character or unfamiliar domain ending is easy to miss, especially when staff communicate with international partners whose addresses they don’t see every day.
Train employees to inspect the full sender address and verify unexpected changes with a known contact. Technical controls also matter: configure SPF, DKIM and DMARC to make it harder for criminals to send email that impersonates your organisation’s domain. These measures won’t stop every lookalike domain, so keep verification procedures in place.
4. Credential-harvesting sign-in pages
Credential phishing can direct staff to a fake website that copies a familiar service. It prompts them to enter login credentials or a multi-factor authentication (MFA) code, allowing information harvesting by an attacker.
Staff should avoid signing in through unexpected email links, as these may be malicious links. Instead, they can open the service through a saved bookmark or type its known address. MFA adds a layer of protection, but the method matters. The NCSC’s corporate MFA guidance describes options for organisations; phishing-resistant methods offer stronger protection than a code an attacker can persuade a user to share.
Cross-channel phishing tactics
Email isn’t the only route into a company. Multi-channel phishing can reach staff by text or phone. Staff need a consistent way to check messages on work devices, personal phones or business calls.
5. Text-message phishing, or smishing
A fraudulent text may claim that a delivery, account or payment needs attention. Cyber criminals may use domain spoofing to direct recipients to a lookalike domain. A link may lead to a fake website, or the message may prompt them to call a number controlled by the sender.
A message that seems relevant to an office in another country may still be fraudulent. Don’t use its link or phone number to check. Contact the organisation using a number or website already known to your team. In the UK, suspicious texts can be forwarded to 7726, as explained in the GOV.UK guidance on reporting phishing.
6. Phone-based pressure
Smishing and vishing are different tactics, but both can create pressure to act. A caller may claim to be from IT, a bank or a supplier and ask an employee to reveal a code, approve a sign-in or install a tool. A voice request can feel persuasive during a handover or outside the usual support hours.
Treat an unexpected call like an unexpected email. End the call and contact the organisation through its published number or your internal service desk. A genuine support team should not need an employee to disclose a one-time code or password.
Phishing through files and routine workflows
Some phishing tactics exploit familiar work habits, such as opening a document or responding quickly to a colleague. This is a form of social engineering, and a believable context doesn’t make a link or attachment safe.
7. Malicious links and attachments
In malware phishing, an email may encourage the recipient to download a file, open an attachment or install software. Some files contain malware, including infostealer malware that can steal information stored on a device. Malicious links may lead to sites designed for information harvesting, such as capturing credentials for cyber criminals.
Be cautious with unexpected invoices, shared documents and software updates, even when they appear to come from a known sender. Confirm the request separately and use approved tools to access files. If a work device opens a suspicious file, contact IT straight away rather than trying to clean it up yourself.
8. Fake requests woven into normal work
An attacker may pose as a colleague or external contact and ask for a document, account access or a change to a process. For example, an employee might receive an unexpected request to share a file with an external address before a deadline. The scenario is illustrative, not evidence that any particular platform or country is being targeted.
Check the recipient and the reason for sharing before granting access. If the request changes normal practice, verify it with the sender through a separate channel. Global teams should use clear, shared procedures for external file sharing and identity checks.
Build controls that work across locations
Security rules only help if every office can follow them. Companies providing global IT support should align reporting and approval processes across sites, while giving staff access to a responsible contact during local working hours.
Set clear verification and reporting rules
Require independent confirmation for payment changes, password resets and requests for sensitive information. Apply zero trust by checking each request through a separate, approved channel, and keep trusted contact details in an approved directory. Reply-to details in a suspicious message aren’t a safe way to verify it.
Use security awareness training to show staff how to report possible phishing without blame. The ICO’s review of phishing incidents highlights the need for staff to know how and where to report. A central process can support multinational IT support teams and local contacts alike.
Combine technical protection with human checks
Use email security tools, including filtering and domain authentication, to help spot domain spoofing and disrupt a phishing campaign. Add MFA and monitor suspicious sign-ins or unusual account activity that cyber criminals may exploit. For organisations with multi-country IT support, agree who reviews alerts, who can disable an account and how urgent incidents pass between teams.
A security audit can identify gaps in access controls, staff processes and incident response. Zero Through offers an IT Security Audit for organisations reviewing their current controls. For ongoing monitoring, its Managed SIEM Services can help security teams detect suspicious activity across systems.
Whether your organisation runs global IT services in-house or works with providers of international IT services, assign clear responsibilities. This helps teams coordinate during a phishing attack, including when cyber criminals use multi-channel phishing to target staff across email, devices and offices. This applies to remote IT support and other IT support services as well as security teams. Organisations arranging IT support for multinational companies or IT support for international businesses should establish consistent escalation routes, rather than relying on a single office to respond. A worldwide IT support rota, international IT support function or global technology support team can each help, provided responsibilities are clear.
What to do after someone responds to a phishing message
Respond quickly, but don’t blame the employee. A phishing attack, including multi-channel phishing, can take different forms. The right steps depend on what happened: clicking malicious links is different from entering details, opening a file or sending money.
Contain account and device risk
Tell IT or security immediately. If login credentials were entered, change the password from a trusted device and anywhere else it was reused. Ask IT to revoke active sessions, review recent sign-ins and check for unexpected email forwarding rules or mailbox access, applying zero trust by verifying access. Report any shared MFA codes or personal details. Cyber criminals may use personal data for information harvesting or to attempt identity theft.
If a file was opened or software installed, disconnect the affected work device from networks if your incident process directs staff to do so, then contact IT. Don’t use the device to change passwords. NCSC guidance advises contacting IT about a work device and running a full antivirus scan when a file or software has been opened.
Report financial loss and suspicious messages
If payment details or banking information were shared, contact the bank promptly. For a suspicious email in the UK, forward it to report@phishing.gov.uk. If money has been lost, follow the relevant UK reporting route: Report Fraud in England, Wales and Northern Ireland, or Police Scotland in Scotland.
Make sure staff in every location know how to report an incident internally, including when the main office is closed. A single reporting route and a clear handover process help incident response teams contain affected accounts and warn colleagues quickly.
Frequently asked questions
What are common phishing tactics used against businesses?
Common methods include payment diversion, impersonation, spoofed sender details, fake sign-in pages, malicious attachments, fraudulent text messages and deceptive phone calls. Cyber criminals often use urgency or authority to pressure staff into skipping checks. If they obtain personal or account details, this can lead to identity theft.
How can international teams check a suspicious payment request?
Use a known, separate channel to confirm the request with the supplier or colleague. Don’t rely on a phone number or link in the message. Require a second approver for changes to supplier bank details and keep that rule consistent across offices. Security awareness training can reinforce these verification habits.
Does MFA stop phishing?
MFA, which may include two-factor authentication, makes stolen passwords less useful, but it doesn’t prevent every attack. Some methods are more resistant to phishing than others. Choose suitable MFA for your organisation and train employees never to share authentication codes.
What should an employee do after clicking a phishing link?
Report a suspected phishing attack to IT straight away, especially if they entered credentials, approved a sign-in, opened a file or installed software. If they only opened a link and took no further action, they should still follow internal reporting rules and stay alert.
Keep verification consistent across borders
Cross-border teams don’t need separate rules for every office, but they do need reliable ways to check urgent requests across time zones. Independently verify payments and account changes, as domain spoofing can make requests appear genuine. Give staff a simple reporting route, and respond quickly if cyber criminals may have exposed credentials or devices.
For help reviewing your controls or support arrangements, Protect Your Business with Zero Through’s cybersecurity services, or Get IT Support for support across multiple locations. You can also Book a Security Review to assess where your processes need attention.


