Original text
European Commission - Press release Three in four EU employees faced cyber threats at work, new Eurobarometer finds Brussels, 30 September 2026 Three in four employees in the European Union encountered suspicious emails, messages or links at work, according to a new Eurobarometer survey published by the European Commission today. The results were released as European Cybersecurity Month begins across all 27 Member St...
European Commission - Press release Three in four EU employees faced cyber threats at work, new Eurobarometer finds Brussels, 30 September 2026 Three in four employees in the European Union encountered suspicious emails, messages or links at work, according to a new Eurobarometer survey published by the European Commission today. The results were released as European Cybersecurity Month begins across all 27 Member States. Phishing was the most common workplace cyber threat, with 39% of employees reporting fraudulent messages or websites designed to steal data or gain unauthorised access. Employees also reported attempts to steal personal data (18%) and passwords (16%), malware attacks (17%), and artificial intelligence (AI)-generated scams (15%). The findings point to a gap between awareness and daily practice. While 83% said the potential consequences of cyberattacks are serious, only 48% said they could recognise an AI-generated fake video. Overall, just 18% said their organisation had experienced no cyber incident at all, as far as they are aware. Awareness is high, but is not mirrored in daily habits E mployees widely recognise risky behaviour, particularly in relation to phishing and password management. Among those using digital systems and tools at work, 76% said clicking on a link without checking the sender is risky . A similar share said using the same password for private and work accounts is risky (74%) , while 69% said sharing work-related information on social media poses a risk . Most employees also know they should report suspicious emails and install software updates. However, this awareness often fails to translate in to daily practice. While 72% said they could identify suspicious emails, o nly 54% said they check the sender before opening links, and just 50% said they always lock their computer when leaving their workstation. Basic cyber hygiene habits , such as checking sender s before opening links and using strong passwords, are common but inconsistent across the workforce , increasing strongly with age . Awareness of c yber - risks also increases significantly with age, highlighting the need for targeted training, particularly for younger employees aged 15 to 24. Organisations need more training and preparedness While most employees believe , according to the survey, that their organisation is effective in protecting against cyberattacks, only around half of organisations have key cybersecurity measures in place, and a further quarter plan to introduce them. Six in ten employees (60%) said they ha d received cybersecurity training in the previous year, although participation drops sharply in smaller organisations. At the same time, 85% sa id they were interested in improving their cybersecurity skills, with lack of time cited as the main barrier by 26%. These results come as the European Union applies cybersecurity rules across critical sectors, connected products and digital services. Background Flash Eurobarometer 576 on ‘ Cybersecurity at the workplace: awareness and preparedness among employees' was conducted online between 27 April and 8 May 2026, interviewing 25,747 EU citizens across all 27 Member States. The survey asked about incidents in the six months before it was conducted. European Cybersecurity Month is an annual cybersecurity campaign promoted by Member States and public and private organisations across Europe, with support from the Commission and ENISA, European Union Agency for Cybersecurity. It raises awareness of online security risks as part of a broader EU policy framework. The EU's wider cybersecurity framework includes the NIS2 Directive , which sets binding cybersecurity obligations across critical and important sectors, and the EU Cybersecurity Act , which established ENISA's permanent mandate and the EU cybersecurity certification framework. The proposed revision of the Cybersecurity Act aims to increase cybersecurity capabilities and resilience, prevent market fragmentation and strengthen the security of the EU's Information and Communication Technologies supply chains. It ensures that products reaching EU citizens are cyber-secure by design through a simpler certification process. The Cyber Resilience Act extends security requirements to connected products and software. The EU Cybersecurity Skills Academy coordinates Europe's response to the cybersecurity skills shortage. The AI Act addresses the security and transparency of AI systems, including those that may be used to generate cyber threats. For more information Flash Eurobarometer 576 EU cybersecurity policies Cybersecurity Skills Academy IP/26/2020 Quote(s): "Today’s Eurobarometer shows that awareness of cybersecurity is high. But understanding the risk is not the same as being prepared for it. Phishing, AI-generated scams and other cyber threats can seriously harm businesses, public services and trust in the digital economy. As European Cybersecurity Month begins, this is a reminder to every citizen, every employer and every organisation that we must move from awareness to action. The Commission is working to strengthen skills, improve preparedness and support stronger cybersecurity measures across Europe. Good cyber hygiene, such as using strong passwords, checking senders before opening links and reporting suspicious messages, must become part of everyday practice." Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy <@rel_link@> Press contacts: Thomas REGNIER (+32 2 299 10 99) Nika BLAZEVIC (+32 2 299 27 17) General public inquiries: Europe Direct by phone 00 800 67 89 10 11 or by email