What is the difference between phishing and blagging? Most people use “phishing” as a catch-all term for any digital scam. Received a suspicious call from someone claiming to be HMRC? Phishing. Got an email asking you to verify your Microsoft account? Phishing. Someone rang your receptionist pretending to be from IT support and asked them to reset a password? Also phishing, apparently.
The problem is that last one is not phishing at all. It is blagging. And treating both attacks as the same thing means your defences have a gap that attackers are actively looking for. At TechVertu, working with SMEs across Essex, London, Surrey and Kent, we see both attacks used against businesses that thought one set of controls was enough. This article explains the real distinction, shows you what each attack looks like in practice, and gives you the steps to take before and after an incident.
- What phishing actually is and its main variants
- Blagging defined: social engineering by story and conversation
- What is the difference between phishing and blagging, technically speaking?
- Real UK examples of phishing and blagging attacks
- Warning signs your team needs to recognise
- Prevention steps and what to do if you are targeted
- Two different attacks, two different defences
What phishing actually is and its main variants
Phishing is a digitally delivered scam. An attacker sends a message, typically by email but also by text or phone, designed to trick the recipient into clicking a malicious link, visiting a fake site, or handing over credentials, banking details, or money. The NCSC describes it as one of the most common cyber threats facing UK businesses, and the 2025/2026 Cyber Security Breaches Survey confirmed it: 93% of businesses that experienced cybercrime had encountered phishing, with an estimated 5.13 million phishing cyber crimes recorded in the previous 12 months.
Phishing is a category, not a single technique. Understanding the variants matters because each one requires a slightly different response.
The difference between mass phishing and spear phishing

Standard phishing casts a wide net. Attackers send thousands of identical messages using generic lures: HMRC rebates, parcel delivery failures, Microsoft account alerts. The volume is the strategy. At scale, even a small fraction of recipients clicking through can make a campaign worthwhile for the attacker.
Spear phishing is different. The attacker researches a specific target, uses their name, job title, company, or recent activity, and crafts a message that feels personal and plausible. It is harder to catch precisely because it does not look generic. When an email addresses you by name and references your current supplier, then arrives from a domain one character off the real thing, the usual red flags are harder to spot.
Vishing and smishing as phishing by another channel
Vishing is phone-based phishing. Smishing is SMS-based phishing. Both still count as phishing because the goal is digital: trick the target into visiting a fake URL or handing over credentials. They are not blagging, and that distinction matters for how you train staff and build defences. A live UK example: according to Which?, almost 5,000 reports of FCA impersonation vishing were logged in the first half of 2025 alone, with callers claiming to be FCA investigators and pressing recipients to act immediately to protect their accounts.
Blagging defined: social engineering by story and conversation
Blagging is when someone makes up a story to gain a person’s interest and draw them into communication. That is the NCSC’s own wording. In cybersecurity, this maps directly to what is widely called pretexting: the attacker constructs a false identity or scenario and uses live conversation to extract information or access. It is a human-to-human attack. No malware, no malicious link, no fake login page. Just a person talking to your member of staff and steering that conversation toward disclosure.
How blagging works in practice
The attacker researches a target organisation first. They find names, job titles, supplier relationships, and organisational structure from LinkedIn, Companies House, a business’s own website, or data exposed in a previous breach. Then they construct a plausible pretext: an IT support contractor doing routine maintenance, an auditor from head office, a new supplier contact chasing a delayed payment, or a facilities engineer needing access to the server room. The call or visit feels routine because the attacker sounds like they belong.
The technique relies on authority, urgency, and rapport, and none of those require a single line of code. There is no malware to detect and no link to scan. The attack succeeds or fails entirely on whether your staff recognise the pattern and know what to do.
Why blagging is not spear phishing
This is a common misconception worth correcting directly. Spear phishing is a targeted digital message. Blagging is live social engineering through conversation, on the phone or in person. The two can work together in a multi-stage attack, where an attacker uses blagging to gather information and then uses that information to craft a convincing spear phishing email. But they are distinct techniques with different indicators and different countermeasures. Treating blagging as just “personalised phishing” means your technical email controls do nothing to stop it.
What is the difference between phishing and blagging, technically speaking?
To answer the question directly: phishing is primarily digital, scalable, and often automated. Blagging is manual, conversational, and targeted at a specific person. One phishing kit can send thousands of messages in hours with almost no additional effort per message. Each blagging attempt requires the attacker to actively engage a real person in real time, which means it is slower, harder to scale, and more selective. That makes phishing far more common by volume, and blagging more damaging per incident when it succeeds.
Both attacks aim to steal something: credentials, money, access, or sensitive data. But the method of deception is fundamentally different. Phishing harvests credentials or payments through deception embedded in a message or website. Blagging extracts information or physical access through deception of a person. That difference shapes how defences must be built. Technical email controls stop phishing. Staff training, verification procedures, and clear escalation paths stop blagging.
Real UK examples of phishing and blagging attacks
Definitions only go so far. Here is what each attack type looks like when it lands in a real UK business.
Phishing examples UK businesses encounter most
HMRC impersonation phishing has resulted in £47 million stolen and approximately 100,000 online accounts compromised, with attackers using stolen identity details to claim rebates whilst posing as legitimate taxpayers. Invoice phishing targets finance teams with fake supplier payment update emails, often timed around genuine invoice cycles to reduce suspicion. Microsoft 365 credential phishing has become increasingly sophisticated: security researchers and vendors including Microsoft itself have documented adversary-in-the-middle toolkits capable of intercepting one-time codes in real time, bypassing standard SMS or app-based two-factor authentication. It is worth noting that phishing-resistant MFA, such as FIDO2 or hardware security keys, is not vulnerable to this technique, which is why it is the recommended standard for high-risk accounts. The FCA impersonation example mentioned earlier, nearly 5,000 reports in six months, shows how quickly a single lure template can generate volume across a wide range of targets.
Blagging attempts that UK SMEs face
Phone-based pretexting is a frequently used form of blagging. A caller claims to be from IT support, a regulator, or a known supplier, and asks a member of staff to confirm account details or reset a password verbally. The caller sounds confident, uses correct terminology, and creates enough urgency that the staff member complies before stopping to verify.
On-site blagging involves someone presenting as a contractor, delivery driver, or facilities engineer to gain physical access to server rooms or unattended workstations. CEO fraud through blagging takes a different route: a caller impersonates a senior director and contacts accounts payable directly, pressuring them to process an urgent transfer before normal approval channels can be followed.
These scenarios are not theoretical. Fraud and impersonation reports from Action Fraud and industry bodies indicate that businesses without trained staff or documented verification procedures are regularly targeted in precisely this way.
Warning signs your team needs to recognise
Recognition is the first line of defence for both attack types, and the cues to look for are genuinely different.
How to spot a phishing email or message
Look for sender domain irregularities: spelling variations, extra characters, or entirely unfamiliar domains. Check links before clicking by hovering to see the actual destination, and treat shortened or mismatched URLs as immediate red flags. Generic salutations in what should be a personal message are a classic tell, as is urgent or threatening language designed to push you into action before you think. Unexpected requests for credentials, payment confirmation, or personal verification should always be treated with suspicion, regardless of how official the branding looks. Spear phishing often eliminates the generic cues entirely, which is why training matters more than checklists alone. If a message feels right but something is slightly off, that instinct is worth acting on.
Recognising a blagging attempt in a call or in person
The behavioural indicators are distinct from anything you would see in an email. Unsolicited contact combined with an implausible or convenient story is the starting point. Pressure to act immediately without following normal verification steps is a key signal: legitimate IT contractors, auditors, and suppliers do not object to being verified through an independent channel. Reluctance to confirm identity through a second route is a significant red flag. Overfamiliarity designed to build false rapport quickly, and requests that break standard procedure, such as asking for passwords verbally or requesting unaccompanied access to a restricted area, are the clearest signs that something is wrong. Staff who know these patterns can pause, verify, and escalate before the attack succeeds. That pause is what your verification procedure exists to enable.
Prevention steps and what to do if you are targeted
The right controls reduce risk before an attack happens. The right playbook limits damage when one does.
Building defences against both attack types
For phishing, the technical baseline includes email filtering with SPF, DKIM, and DMARC configured correctly to reduce the volume of malicious messages reaching inboxes, MFA on all accounts to limit the damage when credentials are stolen, and regular simulated phishing campaigns to test and train staff before a real incident does it for them. A clear incident playbook means staff know exactly what to do when they suspect an attack, rather than improvising under pressure.
Cyber Essentials accreditation confirms that core technical controls, covering secure configuration, access control, malware protection, and firewalls, are in place, and it is increasingly required by clients, insurers, and government procurement frameworks. TechVertu is accredited to certify businesses for both Cyber Essentials and Cyber Essentials Plus, and provides simulated phishing campaigns and co-managed security services for SMEs across the UK. If you have already experienced a breach, TechVertu’s incident response service provides immediate expert support to contain and recover from the incident.
For blagging, the primary defences are human: documented verification procedures for anyone requesting account changes or access, staff training that covers social engineering specifically, and a culture where pausing to verify is treated as good practice rather than unnecessary friction.
Where to report phishing and blagging in the UK
If you receive a suspicious email, forward it to [email protected]. Suspicious text messages should be forwarded to 7726, which is free from all major UK networks. If you have lost money or been hacked, and you are in England, Wales, or Northern Ireland, report to Action Fraud online or by calling 0300 123 2040. In Scotland, contact Police Scotland on 101. If banking details were shared or a payment was made, contact your bank immediately using the number on the back of the card, not a number provided in the suspicious message. Keep all evidence: screenshots, email headers, phone numbers, transaction records, and a timeline of events. That evidence supports the investigation and helps you identify exactly what was accessed or disclosed.
Two different attacks, two different defences
Understanding what is the difference between phishing and blagging is not a theoretical exercise, it determines which controls you actually need. Phishing is digital and scalable; blagging is personal and conversational. Both are common in UK businesses, and both are preventable with the right combination of technical controls, staff training, and clear procedures. The gap between businesses that get targeted successfully and those that do not is usually not technology. It is whether their people knew what they were looking at and what to do next.
If you want to find out how well your business would hold up against either attack type, TechVertu offers simulated phishing tests and security assessments for SMEs across Essex, London, Surrey and Kent. Get in touch with our team to find out where your exposure actually sits.
Lets Talk!
If you have additional comments or questions about this article, you can share them in this section.