Press Release | 19 Nov 2024

Rapid rise in advanced AI-driven phishing attacks is leaving majority of UK business unprepared, according to new Vodafone Business study

The results of the study are a wake-up call for all businesses to strengthen their security measures.

  • 78% of business leaders were ‘confident’ that their employees could successfully identify a sophisticated AI-driven phishing attack, however, two-thirds failed to do so. Younger staff aged 18 to 24 appeared more likely to fall for AI-driven phishing scams than their older peers.
  • Findings revealed during International Fraud Awareness Week (17 – 23 November) as Vodafone Business launches ‘Proactive Security – Phishing of the Future’, a new cybersecurity campaign designed to educate businesses on the emerging threat of AI-driven phishing attacks, as well as the strategies they can employ to help identify, manage and mitigate them.
  • As part of the campaign, Vodafone Business calls on the Government to do more to support businesses on the rising threat of AI-driven phishing scams, including incentivising cybersecurity adoption and reallocating funding for local cybersecurity training.
  • To highlight how cybercriminals are using AI tools to create advanced and convincing phishing scams aimed at businesses, Vodafone Business challenged renowned ‘ethical hacker’ Katie Paxton-Fear to ‘hack’ entrepreneur Chris Donnelly – with the full exchange available to watch via the @VodafoneBusinessUK YouTube Channel.
  • Katie Paxton-Fear also shares her top tips to safeguard your business from advanced AI-driven cyber threats (available in Notes to Editors).

The study of 3,000 combined office workers and business leaders*, from across small, medium and large organisations in the UK, focused on a range of cybersecurity matters. This included their own awareness of, and preparedness for, sophisticated AI-driven phishing attacks.

In today’s fast-paced digital ecosystem, malicious actors are using AI tools to launch increasingly sophisticated and convincing phishing attacks to bypass security and access confidential private or commercial business data.

Due to the simplicity of creating these types of attacks, there has been a significant increase in AI-driven phishing scams against businesses across the UK on a scale not seen before.

The cybersecurity threats facing every small business

For every online threat, there’s a shield to protect your business and your customers – here's everything you need to know, including how Vodafone Business can help.

While a majority (78%) of business leaders felt ‘confident’ their employees could successfully identify an AI-driven phishing attack, the reality was that only a third were able to correctly distinguish a fake, AI-developed video or email from the real thing.

More than half of business leaders (55%) and 45% of office workers admitted they had been targeted by a phishing attempt within the past two years, with 82% of these attacks coming via email, followed by 39% over the phone and 22% on social media.

Last year, there was a 60% global increase in AI-driven phishing attacks, with the UK, United States and India comprising the three countries that suffered the most significant volumes of attacks on businesses. Alongside reputational damage, an average breach could cost an organisation up to £4,200.

To raise greater awareness of the issue during International Fraud Awareness Week, Vodafone Business has launched ‘Proactive Security – Phishing of the Future’, a new cybersecurity campaign designed to educate businesses on the rising threat of AI-driven phishing attacks, as well as the proactive strategies they can employ to help identify, manage and mitigate them successfully.

How V-Hub advisers make cybersecurity simple for small businesses

As a business, you’re never too small to be hacked. In fact, cybercriminals often target smaller companies – especially those serving larger ones – due to more easily exploitable security systems. This Cyber Security Awareness Month, we ask an expert for his top tips and advice.

The study also highlighted an ‘age gap’ in awareness, with younger staff aged 18-to-24 appearing more likely to fall for AI-driven phishing scams than their older peers. Gen Z staff were more likely than most to fall victim, with nearly half (47%) having not updated their password for more than a year, and two-in-10 (19%) having never changed it at all.

Junior staff left themselves the most exposed to hackers, with nearly two-thirds (62%) having social media profiles that were open to the public, compared to two-fifths (40%) of Brits. An open social media account enables hackers to access private information that can be used for criminal activities, while fraudsters can use generative AI tools to replicate a person’s voice with only three seconds of audio.

Steve Knibbs, Head of Vodafone Business Security Enhanced (VBSE), said: “As our campaign highlights, cybercriminals are using AI tools to develop effective and convincing phishing scams, enabling them to create these deceptive communications at a pace and scale not seen before.

“Of course, businesses should be highly aware of the implications of falling victim to cyber scams, which can often lead to drastic reputational and financial consequences.

“I would request businesses of all sizes shore up their around-the-clock cybersecurity protection, by adopting a proactive, multi-layered approach that combines technical safeguards with employee education and AI-driven detection tools that can recognise patterns in phishing attempts.”

Further findings from the Vodafone Business study also revealed that more work was required to ensure office staff were suitably trained to manage more sophisticated AI-driven cyber-attacks. For example:

54%
of UK businesses have no response plan in place to deal with an advanced AI-driven phishing attack.
80%
of businesses agree that cybersecurity training would be helpful for their employees, although only 64% had provided any kind of cybersecurity training in the past two years.
31%
of employees admit their current cybersecurity training needed ‘updating’ to reflect modern forms of cyber-threats powered by AI.
67%
of young workers found their cybersecurity training was not adequately tailored to the needs of their role.
24%
were confident they could successfully identify an image phishing or search engine phishing scam, while only 28% said they could effectively spot a social media scam.
40%
of staff said they would be able to confidently recognise a voice call phishing scam, while 63% said they would identify a text message scam.

Chris Donnelly, entrepreneur, said: “Cybersecurity has always been a priority for my business. It’s something we think about all the time, and we ensure we keep our security protocols as updated as possible.

“You can imagine my surprise then by how effortlessly the ethical hacker was able to breach our defences using sophisticated AI phishing tactics, like voice cloning.

“As someone who runs a tech platform where we manage vast amounts of personal and private data, this experience highlights the importance of staying one step ahead in cybersecurity, especially with evolving AI threats.

“It’s a wake-up call for all businesses to strengthen their security measures and provide consistent training for staff to protect against even the most advanced forms of deception. Today, staying vigilant and adaptive is essential to protecting our organisation and clients.”

Katie Paxton-Fear, Ethical Hacker and Cybersecurity Lecturer at Manchester Metropolitan University, said: “I’m delighted to have partnered with Vodafone Business on this new campaign to drive awareness of the rising threat of AI phishing scams on the business sector.

“Today, cybercriminals have access to powerful artificial intelligence tools that make creating convincing phishing scams alarmingly easy and scalable.

“With AI, attackers can tailor messages to appear highly personalised, making it harder than ever for employees to distinguish a fake email from a legitimate one. Businesses, no matter their size, need to understand the real risk at hand and take proactive measures to defend against these threats.

“Strengthening cybersecurity practices, implementing advanced detection systems, and educating staff on recognising AI-driven scams are essential steps to safeguard valuable data and maintain trust.”

Vodafone Business partnered with renowned Ethical Hacker and Manchester Metropolitan University Lecturer Katie Paxton-Fear and Entrepreneur Chris Donnelly to demonstrate how cybercriminals are using AI to create sophisticated phishing attacks against businesses.
Vodafone Business partnered with renowned Ethical Hacker and Manchester Metropolitan University Lecturer Katie Paxton-Fear and Entrepreneur Chris Donnelly to demonstrate how cybercriminals are using AI to create sophisticated phishing attacks against businesses.

To assist the UK Government in its own mission to better prepare businesses for the rising threat of AI-driven cybersecurity scams, Vodafone Business has outlined several policy recommendations in its ‘Proactive Security – Phishing of the Future’ report, which include:

  1. Incentivising cybersecurity adoption: Introduce financial incentives, such as tax breaks, grants or subsidies, for businesses that invest in cybersecurity measures, including training and certification.
  2. Launching a ‘Cyber Safe’ PR campaign: Develop a nationwide PR campaign to promote Cyber Resilience Centres (CRCs) and the Cyber Essentials certification among businesses of all sizes.
  3. Reallocating funding for local cybersecurity training: Reallocate funds within the National Cyber Security Strategy budget to support targeted local initiatives for businesses, focusing on effective engagement programmes.
  4. Enhancing cybersecurity skills to prevent AI-led cyber-attacks: Promote the development and adoption of AI-driven cybersecurity tools and provide training to businesses on preventing AI-led cyber-attacks.
  5. Expanding Cyber Resilience Centres (CRCs): Establish additional CRCs in underserved regions and enhance the capabilities of existing centres to offer tailored support for businesses.

Find out more about the range of cybersecurity solutions available through Vodafone Business, and help keep your business protected 24/7, by visiting Vodafone Business’ Cyber Security Solutions homepage.

And download the full ‘Proactive Security – Phishing of the Future’ report now.

Stay up to date with the latest news from Vodafone by following us on LinkedIn and Twitter/X, as well as signing up for News Centre website notifications.

-Ends-

Notes to Editors

* In this context, ‘business leaders’ refers to those who either operate their own business or are a C-suite executive.

Research Methodology

Vodafone Business commissioned Walr, an independent market research agency, to conduct online research among 1,000 business leaders and 2,000 office workers aged 18+ across the UK. The fieldwork took place from 3rd to 7th October 2024. Walr employs MRS-certified researchers and strictly adheres to the MRS Code of Conduct.

About Chris Donnelly

Chris Donnelly is a UK entrepreneur, digital creator with over 3 million followers, and founder of The Creator Accelerator, Verb Brands, and Lottie. He also co-hosts the popular business podcast, Secret Leaders podcast. The Creator Accelerator empowers entrepreneurs and creators to build impactful personal brands and engage audiences through organic growth strategies. Learn more at TheCreatorAccelerator.com.

Cybercriminals can’t put the squeeze on this juice business

Mejuicer is a small business, yet its owner nonetheless feels well-prepared to deal with cybersecurity threats, thanks to help from Steven Bartlett and Vodafone Digital SOS.

Top 10 Tips to Help Businesses Counter Advanced AI Phishing Scams:

Ethical Hacker Katie Paxton-Fear shares her top ten tips to help safeguard your business from advanced AI-driven phishing scams:

1. Implement multi-factor authentication (MFA) across all business accounts and systems

The implementation of multi-factor authentication allows businesses to have a safety net so that, even if one account is compromised, there are several walls that the hacker must try and pass before getting into your accounts. This is also a way to alert you to any suspicious activity surrounding your accounts.

2. Keep security software updated

Installing the latest security or software updates places you and your business in the most favourable position to prepare for scammers and hackers. Scams adapt to differing levels of protection and will often find a way to penetrate security walls; however, having the latest update will mean that these security measures will be newer and stronger.

3. Keep passwords updated, unpredictable and undiscoverable

Passwords should be regularly changed so that your account has less chance of being listed on a security breach. These passwords should also all be different and include numbers and symbols to make it harder to breach. A strong password should be as unpredictable as possible, so including your birth year or any findable personal information should be omitted. Passwords should also be undiscoverable. It can be tricky having to remember all your passwords, especially as each account should have a separate one. However, you must not write down these anywhere that a hacker can find them.

4. Educate staff on what to look out for and what they can or can’t make public

Companies should set clear guidelines with employees about what information they are distributing. These businesses should hold regular educational sessions to provide their staff with the security and reassurance that they are not putting themselves or the company at risk of any would-be hacker. Having these measures in place will better prepare the business as a collective against online threats. An effective way to achieve this would be to regularly practice identifying phishing emails through simulated exercises and establish protocols for reporting suspicious activities. The company should also invest in trusted anti-virus and AI-detecting software for peace of mind.

5. Always ask for ID and verification

Although businesses would like to trust everyone that they come into contact with, this is a dangerous approach. Instead, before speaking or communicating with any external party you should always seek verification that the person or company that you are dealing with is authentic. This could be done by asking to see their ID or that they can relay some information to you that only the genuine company would know (as long as it isn’t compromising). You can even try to ask them for some security questions to be sure. Businesses should also consider maintaining and updating a list of approved vendors and their contact information.

6. Never give out personal information

Hackers can be sneaky – they have effective ways of getting you to reveal personal information. In almost every case, giving out personal information will not be a requirement for a genuine company.

7. Keep your friends close

AI scams are increasing significantly, with many scammers now having the technology to impersonate fellow friends and work colleagues’ voices and even faces. If you are in any doubt, always check with the person you know if they sent or tried to speak with you. AI is adapting and evolving rapidly, and identity theft and impersonations are becoming far more convincing and difficult to detect, leaving many businesses vulnerable to hackers and scammers.

8. Be wary of links

In business, and in your personal life, you should always be wary of clicking on links as these are one of the main ways in which hackers breach your security net. If you are unsure, always use a trusted web link checker website to test the validity of the link before clicking it and, once on the website, always try to see if it is listed as a trusted and verified page with a padlock symbol.

9. Encrypt sensitive data

Sensitive data such as bank details or GDPR-related information would be best protected if you encrypt it while using and sending. This way, even if it gets intercepted in transit, a hacker cannot penetrate it.

10. Preparation is key

Finally, it should be good practice to have protocols in place that allow all staff to verify requests. Once this has been established, it will become second nature and create a safer working environment. This also applies to having a contingency plan ready to go if your business has been compromised by a hacker, as it will be safer to deal with and quicker to execute.

About Vodafone UK

Vodafone UK is a technology communications company that connects people, businesses and devices to help our customers benefit from digital innovation. Our services span mobile, fixed-line connections, home and office broadband, and the Internet of Things (IoT).

We have a strong track record as a tech pioneer, making the UK’s first mobile phone call, sending the first text message, and making the UK’s first live holographic call using 5G in 2018. We were the first to start carrying live 5G traffic from a site in Salford, Greater Manchester and now have 5G in locations across Germany, Ireland, Italy, Spain as well as the UK. Meanwhile, our 4G network coverage currently reaches over 99% of the UK population.

Today, Vodafone serves more than 18 million mobile and fixed-line customers in the UK. Vodafone is the largest provider of full fibre in the UK – our superfast broadband services are now available to nearly 12 million homes across the UK.

Sustainability is also at the heart of what we do: as of 1 July 2021, 100% of the grid electricity we use in the UK is certified to be from renewable sources.

For more information about Vodafone UK, please visit: www.vodafone.co.uk.

Vodafone UK Media Relations

Telephone: +44 (0) 1635 693 693

Email: ukmediarelations@vodafone.com

Twitter: @VodafoneUKNews

Website: https://vodafone.co.uk/newscentre/

Vodafone Limited

Registered Office: Vodafone House, The Connection, Newbury, Berkshire RG14 2FN

Registered in England No: 1471587