Three in four employees in the EU encountered suspicious emails, messages or links at work, according to a new Eurobarometer survey published Wednesday by the European Commission.

The results are released as European Cybersecurity Month begins across the 27 EU Member States.
Phishing was the most common workplace cyber threat, with 39% of employees reporting fraudulent messages or websites designed to steal data or gain unauthorised access. Employees also reported attempts to steal personal data (18%) and passwords (16%), malware attacks (17%), and artificial intelligence (AI)-generated scams (15%).
The findings point to a gap between awareness and daily practice. While 83% said the potential consequences of cyberattacks are serious, only 48% said they could recognise an AI-generated fake video. Overall, just 18% said their organisation had experienced no cyber incident at all, as far as they are aware.
European Cybersecurity Month is an annual cybersecurity campaign promoted by Member States and public and private organisations across Europe, with support from the Commission and ENISA, European Union Agency for Cybersecurity. It raises awareness of online security risks as part of a broader EU policy framework.
Employees widely recognise risky behaviour, particularly in relation to phishing and password management. Among those using digital systems and tools at work, 76% said clicking on a link without checking the sender is risky. A similar share said using the same password for private and work accounts is risky (74%), while 69% said sharing work-related information on social media poses a risk. Most employees also know they should report suspicious emails and install software updates.
However, this awareness often fails to translate into daily practice. While 72% said they could identify suspicious emails, only 54% said they check the sender before opening links, and just 50% said they always lock their computer when leaving their workstation.
Basic cyber hygiene habits, such as checking senders before opening links and using strong passwords, are common but inconsistent across the workforce, increasing strongly with age. Awareness of cyber-risks also increases significantly with age, highlighting the need for targeted training, particularly for younger employees aged 15 to 24.
The survey finds that while most employees believe their organisation is effective in protecting against cyberattacks, only around half the organisations have key cybersecurity measures in place, with a further quarter planning to introduce them.
Six in ten employees (60%) said they had received cybersecurity training in the previous year, although participation drops sharply in smaller organisations. At the same time, 85% said they were interested in improving their cybersecurity skills, with lack of time cited as the main barrier by 26%.
Flash Eurobarometer 576 on ‘Cybersecurity at the workplace: awareness and preparedness among employees’ was conducted online between 27 April and 8 May 2026, interviewing 25,747 EU citizens across all 27 Member States. The survey asked about incidents in the six months before it was conducted.






