Phishing Is Changing | September 2026 | EIS News

Spotting a phishing email used to be relatively straightforward. A strange email address, poor spelling or a suspicious-looking link would often give it away. But the attacks we’re seeing now can be much more convincing. 

EIS has recently seen an increase in sophisticated phishing attacks, including some affecting schools and the wider public sector. In some cases, emails are being sent from genuine accounts of someone they know and trust that have already been compromised. This means an email can appear to come from a colleague, supplier or other trusted contact, with little to suggest at first glance that anything is wrong. 

MFA and Payment Fraud

We’re also seeing the potential consequences of cyber attacks become more serious. Recent incidents affecting schools have involved attackers gaining access to payroll details. In some cases, users have been tricked into approving multi-factor authentication (MFA) requests, giving attackers the access they need to enter payroll systems and redirect salary payments.

We’ve also seen emails impersonating genuine suppliers, claiming that their bank details have changed. Where payment details are updated without further checks, schools can unknowingly send payments directly to fraudsters.

With this, It’s becoming more important than ever that school staff know what to look out for.

Why are These Attacks Harder to Spot?

Phishing attacks usually rely on getting someone to click a link, open a document or enter their login details. 

When an attacker has already gained access to a genuine email account, they can use it to send phishing emails to the account holder’s contacts. Because the message comes from a legitimate email address, many of the usual warning signs may be missing. 

Some attacks are also designed to steal the temporary digital tokens created when someone signs in to an online service. These tokens allow people to stay signed in without entering their password every time. 

If a token is stolen, an attacker may be able to access the account without knowing the password or being asked for another multi-factor authentication check.

This means recognising the sender is no longer enough on its own. An unexpected request to open a document, follow a link or sign in to an account is still worth checking, even when the email appears genuine. 

A Phishing Checklist

Before acting on an email, it’s worth checking: 

Was the email expected?

An unexpected document, shared file or request to sign in could be a warning sign.

Does the request make sense?

Even when the sender is familiar, it’s worth considering whether the request is something they would normally make.

Is there pressure to act quickly?

Phishing emails often try to create a sense of urgency.

Where does the link actually go?

Hovering over a link before clicking will show its destination. The address should be checked carefully for misspellings, extra words or anything else that looks unusual.

Is the email asking for a sign-in?

If there is any doubt about a link, the safer option is to open the service or website independently rather than using the link in the email.

Are you being asked to approve an MFA sign-in?

Never approve an unexpected MFA notification or authentication request. If you didn’t initiate the sign-in, stop and report it.

Still unsure?

The request can be checked with the sender another way, using known contact details rather than replying to the email.

Office Employee at Work

What if Someone Has Already Clicked?

If a member of staff thinks they may have clicked on a phishing link, opened a suspicious attachment or entered their login details, it’s important to report it to the school’s IT team or support provider as soon as possible. 

The sooner it’s reported, the sooner any potential risk can be investigated and the right steps taken.

Keeping phishing awareness front of mind can also help. Regular reminders and training give staff the confidence to stop and check when something doesn’t look quite right, even when the email appears to come from someone they know. 

How EIS Can Help

If you or a member of staff believe you’ve interacted with a suspicious email or have concerns about a potential phishing attempt, act quickly.

Schools and organisations with a relevant EIS support contract can contact the EIS Service Desk on 03301 650 000 for direct incident response assistance. For other customers, we’re happy to provide initial guidance and advice. 

For more information on recognising and reporting suspicious emails, visit the National Cyber Security Centre’s phishing guidance.