<15 min Response

Since 2015

Cyber Essentials Certified

Check Your IT Score

Remote SOS Support

Free phishing test • About 2 minutes

Can you spot the phishing email?

This email has just landed in a finance inbox at 4.52pm on a Friday. It hides 8 warning signs. Click or tap every part of it that looks wrong, and see how many you can find before you peek at the answers.

  • 1Read the email
  • 2Click anything suspicious
  • 3Find all 8
Inbox

Brackenford Freight Accounts <accounts@>

Reply-to:

To: accounts@yourbusiness.co.uk

Fri 16:52

Hi,

We are writing regarding invoice BF-20931 for £8,460.00, which is now 14 days overdue.

Regards,
Credit Control Team
Brackenford Freight Ltd

Brackenford Freight and every name, address and link in this example are made up. Nothing in the email is live, so clicking is safe.

The answers

The 8 red flags, explained

Finished the test, or want to check your answers? Here is what each warning sign is and why it matters. If you have not tried the email yet, scroll back up first.

Show the answers
  1. Pressure in the subject line. “Final notice”, “legal action” and a 24 hour deadline. Pressure is there to make you act before you think, and a deadline at the end of a Friday leaves no time to check with anyone.
  2. A lookalike sender address. The name says Brackenford Freight, but the address is brackenf0rd-freight.com, with a zero in place of the letter o. Their genuine emails come from brackenfordfreight.co.uk. Always check the address itself, not just the display name.
  3. Replies go somewhere else. The reply-to address is on a completely different domain. Hit reply and you are talking to the criminal, not your supplier. A reply-to that does not match the sender is a classic sign of invoice fraud.
  4. An attachment that is not really a PDF. The attachment ends in .pdf.htm, so it opens a web page in your browser, usually a fake login form, rather than an invoice. At 3 KB it is also far too small to be a real PDF invoice.
  5. New bank details by email. This is the biggest red flag in the email. Never change who you pay because an email told you to. Call the supplier on a number you already hold, not one taken from the email, and confirm the change before any money moves.
  6. Odd wording and mistakes. “Kindly”, “ammount” and “you’re account”. Mistakes are a clue, but treat them as one clue among several: AI tools now help criminals write clean, convincing emails, so a well written message can still be a scam.
  7. Told not to phone. Being told not to call is designed to stop you checking. A genuine supplier will always be happy for you to ring them on the number you already have.
  8. A link that goes somewhere else. The button says “View invoice securely”, but the link points to brackenford.docs-secure-portal.net and ends in a login page. On a computer, hover over a link to see where it really goes. On a phone, press and hold. If it asks you to sign in, stop.

Invoice and payment scams like this one are covered in more depth in our guide to invoice fraud and business email compromise, and our guide on how to spot a phishing email covers the other common types, from fake password resets to parcel scams.

Why it matters

Phishing is the attack UK businesses meet most

38%of UK businesses experienced phishing attacks in the last 12 months.
69%of businesses and charities hit by a breach or attack said phishing was the most disruptive.
454.8kscam web addresses removed by the NCSC, as of July 2026.

Sources: Cyber Security Breaches Survey 2025/26 (DSIT, April 2026); NCSC.

If it happens for real

What to do if you clicked a phishing link

Clicking happens to careful people. What matters is how quickly you act. These are the steps we give our own clients, in order.

  1. Tell your IT team straight awayThe sooner they know, the sooner they can lock the account, check for unusual sign-ins and stop the damage spreading. Do not wait to see if anything happens.
  2. Change the password, from a different deviceIf you typed a password into the page, change it now from a device you trust, and anywhere else you use the same one.
  3. Call your bank if money or card details are involvedUse the number on the back of your card or your own records, never one from the email.
  4. Report fraud if you have lost moneyIn England, Wales and Northern Ireland, report it to Report Fraud online or on 0300 123 2040. In Scotland, call Police Scotland on 101.
  5. Forward the email to report@phishing.gov.ukThis is the National Cyber Security Centre’s Suspicious Email Reporting Service. It analyses every report and works to take scam sites down.
  6. Then delete itOnce IT and the NCSC have it, delete the email so nobody else on the team clicks it by mistake.

For your whole team

One person spotting a scam is good. A whole team that stops and checks is better.

Criminals only need one person to click. That is why we protect businesses in layers: email filtering to stop most phishing before it reaches an inbox, phishing-resistant multi-factor authentication so a stolen password is not enough on its own, and staff awareness training with phishing simulations, so you can see who would click before a criminal finds out.

See how it fits together on our cyber security services page, or book a free review below and we will tell you where your gaps are.

Send this test to your team

It takes about two minutes, works on any phone and nothing in it is live. A quick way to start a conversation about phishing.

Email it to your teamatsconnection.co.uk/phishing-test/

Free • No obligation • Senior engineer • 30 minutes

Find out how exposed your business really is

A senior engineer will look at your email security, Microsoft 365 sign-in settings and backups with you, and tell you plainly what would stop a phishing email like this one, and what would not.

What you get from the review

  • Email filtering and sign-in security checked
  • Multi-factor authentication gaps flagged
  • Backups checked against ransomware
  • A plain-English list of what to fix first

Book your free IT & cyber review

Free, no obligation. We only use your details to arrange the review. Privacy policy.

FAQ

Phishing tests: common questions

A phishing test checks whether someone can recognise a phishing email before acting on it. This one shows a realistic but made-up invoice scam with 8 hidden warning signs. Businesses also run phishing simulations, where safe test emails are sent to staff to see who clicks, followed by short training for anyone who does.

No. Brackenford Freight and every name, address and link in the example are invented. Nothing in it is live, so clicking any part of it is safe. It is based on the way real invoice and payment scams are written.

Start by sharing this page so the team knows the warning signs. For a proper picture, a phishing simulation sends safe test emails to staff and reports who opened, clicked or entered a password, so training can be aimed where it is needed. We run awareness training and phishing simulations as part of our cyber security services.

Tell your IT team straight away, change the password from a different trusted device if you entered one, and call your bank if money or card details are involved. If you have lost money, report it to Report Fraud on 0300 123 2040, or Police Scotland on 101 in Scotland.

Forward it to report@phishing.gov.uk, the National Cyber Security Centre’s Suspicious Email Reporting Service, and tell your own IT team. Then delete it so nobody else clicks it.

Not completely. Good email filtering stops most phishing before it reaches an inbox, and phishing-resistant multi-factor authentication means a stolen password is not enough on its own, but some emails will still get through. That is why staff awareness matters as the last line of defence.

Because it is how invoice fraud works. Criminals pose as a real supplier and ask you to pay a genuine invoice into their account instead. Always confirm any change of bank details by phone, using a number you already hold, before paying. Our guide to invoice fraud explains more.