Politics Business Culture Technology Environment Travel World
Home› Technology› Feature
Technology · Exclusive

Phishing hits three-quarters of EU workers, survey shows

Phishing hits three-quarters of EU workers, survey shows
Technology · 2026
Photo · Kai Lindgren for European Pulse
By Kai Lindgren Technology Editor Oct 9, 2026 3 min read

Phishing has become a near-universal experience in European workplaces, according to a new Eurobarometer survey released by the European Commission on 30 September. The findings, timed to coincide with European Cybersecurity Month, show that 75% of employees across the European Union have encountered suspicious emails, messages, or links during their professional lives.

The Hellenic Data Protection Authority (HDPA) in Greece has used the data to press both public bodies and private firms to treat personal data protection as a core part of their cyber defences. The survey paints a picture of a workforce that is aware of digital risks but often fails to act on that knowledge.

Phishing remains the dominant threat

Fraudulent messages and fake websites designed to steal credentials or gain unauthorised access remain the most common attack vector, reported by 39% of respondents. Attempts to harvest personal data follow at 18%, with malware attacks at 17% and password theft at 16%.

AI-powered scams are also on the rise, with 15% of workers saying they have already encountered them. As generative tools become more accessible, attackers can craft increasingly convincing messages, images, and voice recordings, making detection harder for the average employee.

Knowledge gap between awareness and action

While 83% of employees acknowledge that a cyberattack could have serious consequences, and 72% believe they can spot a suspicious email, only 54% actually check the sender before clicking a link. The gap is even wider for AI-generated content: fewer than half (48%) say they could recognise a deepfake video.

This disconnect is a concern for regulators like the HDPA, which argues that cybersecurity is no longer a purely technical issue but a daily responsibility for every organisation handling personal data.

GDPR obligations when breaches occur

Under Article 33 of the General Data Protection Regulation (GDPR), organisations must notify the relevant supervisory authority of a breach. But the HDPA stresses that compliance does not end there. Article 34 requires them to inform affected individuals without undue delay when the breach poses a high risk to their rights and freedoms, such as financial fraud, identity theft, or exposure of sensitive data.

Prompt notification gives people the chance to take protective steps, such as changing passwords, cancelling bank cards, or staying alert for suspicious activity. Delaying or hiding a breach can leave victims more exposed, undermining trust in the organisation.

Transparency, the HDPA argues, is not just a legal obligation but a cornerstone of public confidence. As winter pressures on infrastructure mount, the need for robust cyber hygiene becomes even more critical.

A call for preparedness

The HDPA is urging organisations to review their incident response plans, train staff regularly, and integrate data protection into every stage of handling a breach. With three in four workers already exposed to phishing attempts, the message is clear: cybersecurity must be embedded in daily operations, not treated as an afterthought.

As European institutions and member states grapple with expanding digital trade routes, the resilience of the workforce against cyber threats will be a key factor in maintaining economic stability.

More from this story

Next article · Don't miss

Rare twin waterspout hits western Sicily, injuring two and damaging schools

A rare double waterspout formed off the coast of Marsala, Sicily, before moving inland and causing damage to buildings, vehicles, and farmland. Two people were injured when their car was thrown into a ravine in Petrosino.

Read the story →
Rare twin waterspout hits western Sicily, injuring two and damaging schools