Skip to main content

6 Ways to Combat Social Media Phishing Attacks in 2026

Media 6 Ways to Combat Social Phishing Attacks

 

Phishing does not only arrive in your email inbox.

Criminals increasingly use LinkedIn, Facebook, Instagram, WhatsApp, Messenger and other social and messaging platforms to impersonate real people, build trust and persuade victims to click malicious links, reveal credentials or transfer money.

For businesses, the risk is particularly important because social media provides attackers with something extremely useful:

information.

Job titles. Colleagues. Customers. Suppliers. Projects. Events. New starters. Senior management. Company announcements.

Those details can help an attacker create a far more convincing phishing approach.

The NCSC specifically warns that criminals can use information published on social media to make phishing messages more believable. It also advises organisations and individuals to review how much information they expose publicly and to consider the security of their social-media accounts.

Phishing remains one of the biggest cyber threats facing UK organisations. The Government's Cyber Security Breaches Survey 2025/26 found that 38% of UK businesses experienced phishing during the previous 12 months, making it by far the most commonly identified type of cyber attack or breach.

Here are six practical ways businesses and employees can reduce the risk of social-media phishing in 2026.

1. Be Careful About What You Publish

Social engineering works much better when the attacker knows something about the victim.

Imagine an employee posts on LinkedIn:

> Delighted to have joined Hamilton & Co as Finance Manager. Looking forward to working with our new MD, James!

 

That sounds harmless.

But a criminal now knows:

The employee is new.

They work in finance.

They may not yet understand internal procedures.

They know the managing director's name.

They may have authority around payments.


A few days later, the employee receives a LinkedIn message apparently from James:

> Hi, I'm in meetings all afternoon. Can you sort an urgent supplier payment for me?

 

That is much more believable than a random phishing email.

The NCSC advises businesses to think carefully about what personal and organisational information appears online because attackers can use it when preparing spear-phishing attacks.

This does not mean your employees should disappear from LinkedIn.

For many companies, social media is an important marketing, recruitment and networking tool.

Instead, think about information value.

Avoid unnecessarily publishing:

Internal system details.

Employee contact information.

Detailed organisational structures.

Travel arrangements.

Security procedures.

Information about privileged accounts.

Too much information about upcoming payments or projects.

Public information should have a business purpose.

2. Treat Unexpected Direct Messages Like Unexpected Emails

A message arriving through LinkedIn does not become trustworthy simply because it arrived through LinkedIn.

Neither does a WhatsApp message.

Or Instagram.

Or Facebook Messenger.

Social phishing often begins with something innocent.

“Hi, I'd like to discuss your services.”

Then:

“Here's our specification.”

Then a link.

Or perhaps:

“I think somebody is using your photos. Is this you?”

Link.

Or:

“Can you review this document before our meeting?”

Link.

The NCSC's phishing guidance recommends designing organisations so that phishing does not depend entirely on employees successfully recognising every malicious message. Technical controls should make attacks harder to deliver and harder to exploit when somebody does interact with them.

Employees should therefore apply the same basic rules to social messages that they would to email.

Was I expecting this?

Does the request make sense?

Why do I need to log in?

Why is this urgent?

Can I verify the person another way?

And crucially:

Do I actually need to click this link?

If somebody sends you a Microsoft 365 link claiming you need to authenticate, consider accessing Microsoft 365 independently instead.

If a supposed customer sends a suspicious file, verify them before opening it.

3. Verify People Before You Trust Their Profile

Fake profiles are no longer necessarily obvious.

An attacker can copy:

A person's name.

Profile photograph.

Job history.

Company information.

Connections.

Public posts.

They can then approach employees or customers while appearing to be someone genuine.

The NCSC warns that attackers may impersonate other people on social platforms even when a profile appears to have mutual contacts.

That makes:

“We have three mutual connections.”

a weak form of identity verification.

For important requests, use another trusted channel.

For example, if your finance director apparently contacts you through LinkedIn asking for something unusual, telephone them using the number already stored in your company directory.

Don't use a telephone number supplied inside the suspicious conversation.

The same principle applies to suppliers.

A message saying:

“We've changed our bank account details.”

should trigger independent verification.

Payment changes should not be authorised merely because the profile picture looks correct.

4. Secure Social and Messaging Accounts Properly

Social-media account compromise can become a business-security problem.

Imagine an attacker takes control of your company's LinkedIn account.

They may potentially:

Impersonate your organisation.

Message customers.

Publish fraudulent links.

Damage your reputation.

Attempt to steal credentials.

Target employees or followers who already trust the brand.

The NCSC advises organisations to restrict publishing access to authorised employees, enable stronger account security features and maintain a recovery plan for corporate social-media accounts.

At a minimum, review:

Who has access?

Former employees should not still control business accounts.

Are passwords unique?

Do not reuse the same password across multiple services.

Is MFA enabled?

Where available, enable strong authentication.

Are passkeys available?

The NCSC now recommends passkeys as a particularly strong authentication option because they are resistant to conventional phishing.

Is account recovery information current?

An old employee's personal email address should not be the only recovery method for your corporate Instagram account.

Do agencies need the actual password?

Where possible, use role-based platform or social-media management access instead of handing one shared password to everybody.

5. Expect AI-Assisted Impersonation and Deepfakes

One of the biggest changes since older social-phishing advice was written is the rapid improvement in generative AI.

The traditional advice:

“Look for poor spelling.”

is nowhere near enough anymore.

AI can help criminals generate professional-looking messages, translate them effectively and create believable conversations at scale.

The NCSC assesses that AI is increasing attackers' capabilities in areas including social engineering, making convincing interactions and phishing material easier to produce.

Employees should therefore judge a request based on its context and behaviour, not merely how professional it looks.

You should also prepare people for:

AI-generated profile photographs.

Fake documents.

Voice cloning.

Manipulated video.

Impersonation over messaging apps.

The NCSC already advises higher-risk users to expect attackers to make increasing use of voice cloning and deepfake techniques.

Imagine receiving a WhatsApp voice message from your managing director saying:

“I'm boarding a flight. Please pay this invoice now.”

The voice sounds right.

Does that prove it is genuine?

Increasingly, no.

High-risk actions should have independent verification procedures regardless of how convincing the message, voice or image appears.

6. Make Social Phishing Part of Your Security Training

Many cyber-awareness programmes focus almost entirely on email.

Employees learn to identify:

Fake invoices.

Microsoft password resets.

Malicious attachments.

Suspicious URLs.

Then they receive an almost identical attack through LinkedIn and lower their guard.

Your training should make clear that phishing can arrive through:

Email.

SMS.

WhatsApp.

LinkedIn.

Facebook.

Instagram.

Teams.

QR codes.

Telephone calls.

Online adverts.

The NCSC's current phishing reporting guidance itself covers emails, texts, websites, adverts and phone calls, reflecting how broad modern scam delivery has become.

Training should also include realistic scenarios.

For example:

The Fake Recruiter

A LinkedIn recruiter approaches an employee with an attractive job opportunity and sends a document or login link.

The Fake Customer

A new connection asks for a quote and supplies a link supposedly containing specifications.

The Fake Director

An apparently genuine executive profile asks an employee to make an urgent purchase or payment.

The Compromised Contact

A genuine friend or colleague's social-media account is taken over and sends malicious messages.

The QR Code

A message asks the employee to scan a QR code to join a meeting or authenticate an account.

The NCSC has specifically warned users not to share authentication codes or scan unexpected QR codes that could allow attackers to add their own devices to messaging accounts.

Social Media Privacy Helps — but It Isn't a Complete Solution

The original version of this article heavily recommended making social-media accounts private and hiding friends lists.

That can help.

But it isn't always practical for business users.

A salesperson may need a public LinkedIn profile.

A company LinkedIn page obviously needs to be visible.

A marketing manager may actively want customers finding them.

Security therefore cannot depend entirely on privacy settings.

Instead, think in layers:

Limit unnecessary information.

Secure accounts.

Verify unusual requests.

Train employees.

Protect devices.

Use phishing-resistant authentication.

Make reporting easy.

That gives the organisation multiple opportunities to stop an attack.

Don't Assume Social-Media Links Automatically Install Malware

Another area where older phishing advice needs updating is the idea that clicking a phishing link will immediately infect a device.

That can happen in some circumstances, but many modern phishing attacks do something simpler:

They steal your login details.

A user clicks a link.

They see what appears to be Microsoft 365.

They enter:

Email address.

Password.

MFA information.

The attacker tries to use those credentials.

This is one reason phishing-resistant authentication matters.

In April 2026, the NCSC strengthened its recommendation around passkeys, explaining that unlike passwords and traditional authentication methods, passkeys are cryptographically bound to the legitimate service and cannot simply be handed over to a fake website.

Businesses should increasingly consider passkeys or FIDO2 authentication for important and privileged accounts where supported.

What If an Employee Already Clicked?

The most important thing is:

Tell IT quickly.

Do not hide it.

Do not spend an hour trying to decide whether you should mention it.

If the employee entered credentials, IT may need to:

Reset authentication.

Review login activity.

Revoke active sessions.

Check MFA methods.

Investigate mailbox or cloud activity.

Inspect the endpoint.

Search for similar messages sent to other employees.

If money was transferred or sensitive information was disclosed, additional response steps may be necessary.

The NCSC encourages people to report phishing attempts because reports can be used to identify and remove malicious infrastructure. As of July 2026, its scam-reporting service had received more than 58 million reports, contributing to the removal of hundreds of thousands of scams.

For organisations, internal reporting is just as important.

Employees need to know exactly who to contact.

Build Technology Around Your Employees

Employees should be trained.

But your entire defence should not be:

“Hopefully nobody clicks anything.”

The NCSC recommends a layered approach to phishing defence.

For businesses, appropriate controls might include:

Passkeys or phishing-resistant MFA

Microsoft Entra Conditional Access

Endpoint Detection and Response

DNS and web filtering

Managed devices

Patch management

Email and web security

Least-privilege access

Security monitoring

If one employee makes one mistake, another security control should ideally prevent that mistake becoming a serious compromise.

Social Phishing in 2026: The Key Lesson

The biggest change in social phishing is that criminals no longer need their first message to look suspicious.

They can research you.

Copy somebody you know.

Create a convincing profile.

Generate professional messages with AI.

Build trust over several conversations.

Then introduce the malicious request.

That means employees need to stop judging trust purely by appearance.

A familiar photograph does not prove identity.

A professional LinkedIn profile does not prove identity.

A perfectly written message does not prove identity.

Even a convincing voice may increasingly not prove identity.

When the request involves money, passwords, authentication, confidential information or an unusual business action, verify it independently.

Protect Your Business From Phishing With Hamilton Group

Hamilton Group can help businesses build stronger protection against phishing, social engineering, account compromise and identity-based attacks.

We can help with cyber-security awareness training, Microsoft 365 security, Microsoft Entra ID, Conditional Access, passkeys and phishing-resistant MFA, EDR, DNS and web filtering, managed devices, security monitoring and managed IT support.

The objective isn't to expect every employee to identify every sophisticated scam perfectly.

It is to combine trained people with strong technical controls, so one convincing message does not automatically become a major business incident.

And when an employee does receive something suspicious — or thinks they may already have clicked it — our aim is to make first contact on IT support requests within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.