Warning: Don’t fall for fake CAPTCHAs
Most people don’t think twice about CAPTCHAs. And that’s being exploited. There’s a new twist on something you see every day. It’s catching people out in a way that only shows up later…
VideoCybercriminals are getting smarter, and phishing attacks are becoming more sophisticated. These attacks target businesses of all sizes, aiming to steal sensitive information such as passwords, payment details, or personal data. Recently, attackers have started using neglected or abandoned domains to bypass email security systems. This makes it harder for traditional security measures to detect and block their malicious emails. Here’s what’s happening and how you can protect your business.

Phishing involves cybercriminals sending fake emails that look like they’re from trusted organisations. These emails are designed to trick recipients into taking harmful actions, like clicking on a malicious link, scanning a QR code, or providing personal information.
The latest trend involves attackers exploiting neglected domains—web addresses that are no longer actively used or managed. These domains often lack DNS (Domain Name System) records, which include security measures like Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). These records verify that an email is genuinely from the sender’s domain. Without them, fake emails can easily bypass security filters and reach your inbox.
Some phishing campaigns also use QR codes to lure victims. These codes often lead to fake websites that mimic official pages, such as login portals for banks or government services. To make the scam more believable, attackers may include a password in the email to “unlock” the QR code, adding an extra layer of deception.
Small businesses are especially vulnerable to phishing attacks. Unlike larger companies, small businesses often lack the advanced cybersecurity systems needed to detect and block these threats.
The consequences of falling victim to a phishing attack can be severe. Hackers may steal sensitive data, access your bank accounts, or compromise your customers’ information. This could lead to financial losses, reputational damage, and potential legal issues.
In addition to the risks of falling victim to phishing, there’s also a significant reputation risk if one of your own business domains is used in an attack. Cybercriminals can exploit neglected or abandoned domains to send phishing emails that appear to come from your business. If this happens, your clients, partners, or other contacts could lose trust in your organisation. Rebuilding that trust can take time and effort, not to mention the damage it may cause to your brand’s image.
Protecting your business from phishing attacks doesn’t have to be complicated. Here are some simple steps you can take:
Even if your business doesn’t have a dedicated IT team, there are simple tools you can use to protect yourself:
Phishing attacks rely on human error. By staying vigilant and taking precautions, you can reduce the risk of falling victim to these scams. If you’re ever unsure about an email, contact the organisation directly using a phone number or website you trust—not the contact details in the email. Cybersecurity doesn’t have to be overwhelming; small steps can make a big difference in keeping your business safe.
Managing Director, Westway IT
John is the founder of Westway IT and works directly with small businesses across Gloucestershire to keep their IT secure, productive and stress-free.
With a BSc in Computer Science and hands-on experience supporting businesses from 1 to 40 users, he specialises in cyber security, Microsoft 365 and business automation.
An award-winning MSP owner and active member of the global IT community (including GTIA), John focuses on solving real business problems, not just technical ones.
Published: 10 January 2025 | Last Updated: 10 January 2025