Three in Four EU Workers Faced Cyber Threats at Work, Survey Finds

European Commission

Three in four employees in the European Union encountered suspicious emails, messages or links at work, according to a new Eurobarometer survey published by the European Commission today. The results were released as European Cybersecurity Month begins across all 27 Member States.

Phishing was the most common workplace cyber threat, with 39% of employees reporting fraudulent messages or websites designed to steal data or gain unauthorised access. Employees also reported attempts to steal personal data (18%) and passwords (16%), malware attacks (17%), and artificial intelligence (AI)-generated scams (15%).

The findings point to a gap between awareness and daily practice. While 83% said the potential consequences of cyberattacks are serious, only 48% said they could recognise an AI-generated fake video. Overall, just 18% said their organisation had experienced no cyber incident at all, as far as they are aware.

Awareness is high, but is not mirrored in daily habits

Employees widely recognise risky behaviour, particularly in relation to phishing and password management. Among those using digital systems and tools at work, 76% said clicking on a link without checking the sender is risky. A similar share said using the same password for private and work accounts is risky (74%), while 69% said sharing work-related information on social media poses a risk. Most employees also know they should report suspicious emails and install software updates.

However, this awareness often fails to translate into daily practice. While 72% said they could identify suspicious emails, only 54% said they check the sender before opening links, and just 50% said they always lock their computer when leaving their workstation.

Basic cyber hygiene habits, such as checking senders before opening links and using strong passwords, are common but inconsistent across the workforce, increasing strongly with age. Awareness of cyber-risks also increases significantly with age, highlighting the need for targeted training, particularly for younger employees aged 15 to 24.

Organisations need more training and preparedness

While most employees believe, according to the survey, that their organisation is effective in protecting against cyberattacks, only around half of organisations have key cybersecurity measures in place, and a further quarter plan to introduce them.

Six in ten employees (60%) said they had received cybersecurity training in the previous year, although participation drops sharply in smaller organisations. At the same time, 85% said they were interested in improving their cybersecurity skills, with lack of time cited as the main barrier by 26%.

These results come as the European Union applies cybersecurity rules across critical sectors, connected products and digital services.

Background

Flash Eurobarometer 576 on 'Cybersecurity at the workplace: awareness and preparedness among employees' was conducted online between 27 April and 8 May 2026, interviewing 25,747 EU citizens across all 27 Member States. The survey asked about incidents in the six months before it was conducted.

European Cybersecurity Month is an annual cybersecurity campaign promoted by Member States and public and private organisations across Europe, with support from the Commission and ENISA, European Union Agency for Cybersecurity. It raises awareness of online security risks as part of a broader EU policy framework.

The EU's wider cybersecurity framework includes the NIS2 Directive , which sets binding cybersecurity obligations across critical and important sectors, and the EU Cybersecurity Act , which established ENISA's permanent mandate and the EU cybersecurity certification framework. The proposed revision of the Cybersecurity Act aims to increase cybersecurity capabilities and resilience, prevent market fragmentation and strengthen the security of the EU's Information and Communication Technologies supply chains. It ensures that products reaching EU citizens are cyber-secure by design through a simpler certification process. The Cyber Resilience Act extends security requirements to connected products and software. The EU Cybersecurity Skills Academy coordinates Europe's response to the cybersecurity skills shortage. The AI Act addresses the security and transparency of AI systems, including those that may be used to generate cyber threats.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.