Phishing Remains Europe’s Top Cyber Threat as Workers Struggle to Spot Deepfakes

Web Reporter
4 Min Read

Three in four workers across the European Union have encountered suspicious emails, messages or links at work, while fewer than half believe they can identify a deepfake video, according to a Eurobarometer survey published by the European Commission on September 30.

The findings highlight the growing exposure of employees to cyber threats and the gap between awareness of online risks and everyday security practices. Greece’s Hellenic Data Protection Authority (HDPA) has used the results to urge public bodies and private companies to strengthen cybersecurity measures and improve the protection of personal information.

The survey was released as European Cybersecurity Month began, an initiative aimed at raising awareness of digital threats and encouraging safer online behaviour.

Phishing remains the most frequently reported cyber threat. Some 39 per cent of employees said they had received fraudulent messages or been directed to fake websites designed to steal information or gain unauthorised access to systems.

Attempts to steal personal data were reported by 18 per cent of respondents, while 17 per cent had encountered malware attacks and 16 per cent reported attempts to obtain passwords.

Artificial intelligence is also creating new challenges. Around 15 per cent of employees said they had encountered scams powered by AI, which can help criminals produce convincing messages, images, voices and videos to deceive victims.

Despite widespread exposure to suspicious communications, many workers remain uncertain about how to respond safely. The survey found that 83 per cent understood that cyberattacks could have serious consequences, and 72 per cent said they could recognise a suspicious email.

However, only 54 per cent said they checked the sender’s identity before clicking on a link. The ability to identify manipulated content was also limited, with just 48 per cent saying they could recognise a deepfake video.

The HDPA said organisations must address these weaknesses through regular staff training and stronger procedures for responding to security incidents. It also stressed that cybersecurity involves more than resolving technical problems, particularly when personal data has been exposed.

Under Article 33 of the European Union’s General Data Protection Regulation (GDPR), organisations responsible for processing personal data must notify the relevant supervisory authority of a personal data breach, subject to the regulation’s requirements and exceptions.

Article 34 requires organisations to inform affected individuals without undue delay when a breach is likely to pose a high risk to their rights and freedoms.

Such incidents can expose people to financial fraud, identity theft and the disclosure of sensitive information. Prompt notification allows those affected to take protective measures, including changing passwords, cancelling compromised bank cards and monitoring accounts for suspicious activity.

The authority warned that withholding information or delaying notification without a valid reason could leave individuals vulnerable to further harm.

Transparency also plays an important role in maintaining trust between organisations and the people whose information they hold.

The HDPA is calling on public institutions and private businesses to review their incident response plans, train employees regularly and include data protection measures throughout the handling of cybersecurity incidents.

With suspicious messages already a common feature of working life, the authority said organisations must treat digital security as an ongoing responsibility rather than a purely technical concern.

TAGGED:
Share This Article
Leave a comment

Leave a Reply