Summary
- A Commission survey found 75% of EU employees encountered suspicious messages, links, or other cyber threats at work during the preceding six months.
- Phishing was the most commonly reported threat at 39%, while 15% of respondents encountered AI-generated or AI-enabled scams.
- Six in ten employees received cybersecurity training during the previous year, but everyday security practices remain markedly less consistent than awareness.
Three quarters of employees across the European Union say they encountered suspicious messages, links, or other cyber threats at work during a six-month period, while the gap between knowing basic security rules and consistently following them remains stubbornly wide.
The findings come from Flash Eurobarometer 576, published by the European Commission, which surveyed 25,747 people across all 27 EU Member States between 27 April and 8 May 2026. Respondents were asked about incidents encountered during the preceding six months, making the results a measure of reported exposure rather than a real-time count of successful cyberattacks.
Phishing dominated the responses, with 39% of employees reporting fraudulent messages or websites intended to steal information or gain unauthorised access. Attempts to obtain personal data were reported by 18%, malware by 17%, password theft by 16%, and AI-generated or AI-enabled scams by 15%.
Those categories should not be treated as confirmed breaches, nor can they simply be added together. An employee receiving a malicious email that is filtered, deleted, or reported has still encountered a threat without the organisation necessarily being compromised, while the same person may have experienced several different forms of attack.
Awareness is not yet routine
Although 83% of respondents considered the possible consequences of a cyberattack serious, the survey found a less consistent picture when employees were asked what they actually do during an ordinary working day. Among people using digital systems at work, 76% recognised the risk of clicking a link without first checking the sender, while 74% regarded reusing the same password across personal and professional accounts as risky.
Yet only 54% said they check the sender before opening links, despite 72% saying they know how to identify suspicious emails. Half said they always lock their computer when moving away from their workstation, showing how familiar security instructions become less reliable once they compete with deadlines, interruptions, and routine working habits.
The distinction is consequential for organisations that have treated employee awareness mainly as a communications problem. Annual training can establish that phishing is dangerous, but it does not automatically make checking a sender, reporting an unexpected request, or locking a device the default behaviour when an employee is busy.
The Commission also found that reported awareness and some cyber-hygiene practices tended to improve with age, with younger employees aged 15 to 24 identified as a group for more targeted training. Because the finding reflects self-reported behaviour rather than controlled testing, it should not be taken as proof that one age group is intrinsically better at detecting attacks.
Training coverage remains uneven
Six in ten employees said they had received cybersecurity training during the previous 12 months, although participation fell among smaller organisations. At the same time, 85% said they were interested in improving their cybersecurity skills, with lack of time cited as the most common obstacle by 26% of respondents.
That combination creates an operational problem. Interest in security training is relatively high, but organisations still need to make time for it, adapt it to the attacks employees actually encounter, and reinforce behaviour after the course has finished. Smaller businesses face an additional constraint because specialist teams, formal training budgets, and dedicated security support are less likely to be spread across a large workforce.
The survey also found that employees generally considered their organisations effective at protecting them from cyberattacks, while only around half reported that their employer had implemented a range of important cybersecurity measures and roughly another quarter said measures were planned. Since employees may not see controls operating behind the scenes, those figures are better treated as perceptions of organisational preparedness than as a technical audit.
Likewise, only 18% said their organisation had experienced no cyber incident at all, as far as they knew. The wording is important: encountering an attempted phishing attack is not the same as suffering a breach, and employees will not necessarily know about incidents handled by security teams elsewhere in an organisation.
AI adds another impersonation problem
Artificial intelligence is already visible in the threat mix, with 15% of respondents reporting AI-generated scams, while fewer than half — 48% — believed they could recognise an AI-generated fake video. The second figure is a self-assessment rather than the result of a detection test, but it captures the uncertainty created as synthetic images, voices, and video become cheaper to produce.
Attackers do not need every generated artefact to be convincing. Fraud already relies heavily on urgency, authority, familiarity, and the assumption that an email, message, or call came from the person it claims to represent. Cheap synthetic media gives attackers another way to reinforce those cues, particularly where organisations rely on informal approval processes or employees routinely act on instructions delivered through several communications channels.
The practical response therefore extends beyond teaching employees to look for visual glitches in generated video. Organisations can reduce the value of impersonation by making sensitive requests independently verifiable, separating communication from authorisation, and ensuring that payment changes, credential resets, and access requests do not depend on recognising whether a voice, message, or image appears genuine.
Published as European Cybersecurity Month begins, the Eurobarometer describes a workforce that largely understands cyber risk but still encounters malicious activity as part of ordinary digital work. The harder task sits between awareness and execution: turning familiar guidance about links, passwords, devices, and suspicious requests into routines that continue to function when employees are distracted, rushed, or presented with something unusually convincing.












