Summary
- Seventy-five per cent of EU employees reported encountering suspicious emails, messages, or links at work.
- Phishing was reported by 39%, malware attempts by 17%, and AI-generated scams by 15%.
- Only 48% said they could recognise an AI-generated fake video, highlighting uneven confidence as synthetic content enters workplace fraud.
Three quarters of employees in the European Union encountered suspicious emails, messages, or links at work, according to a new Eurobarometer survey that provides a bloc-wide measure of how routinely organisations are exposed to digital fraud and malicious content.
The European Commission published the findings on 30 September as European Cybersecurity Month began across all 27 member states.
Phishing was the most common threat reported, with 39% of employees saying they had encountered fraudulent messages or websites intended to steal information or obtain unauthorised access. Seventeen per cent reported malware attacks, 18% attempts to steal personal information, and 16% efforts to obtain passwords.
AI-generated scams were encountered by 15% of respondents.
The survey also found a gap between recognising cyber risk in principle and confidence around newer forms of deception. While 83% considered the possible consequences of cyberattacks serious, only 48% said they could recognise a fake video generated using artificial intelligence.
Just 18% said their organisation had experienced no cyber incident at all, as far as they were aware.
The figures do not mean three quarters of European workers were successfully compromised. Encountering a suspicious email or link is an exposure measure, not a breach count. It does, however, show how frequently organisations still depend on employees to make security decisions during normal work.
That dependence is becoming harder to manage as social engineering expands beyond obviously fraudulent email. Generative AI can reduce the effort required to produce plausible text, audio, images, and video, while workplace communications increasingly move between email, collaboration platforms, mobile messaging, and video calls.
The 48% figure for synthetic video is therefore notable because false media can reinforce payment fraud, executive impersonation, credential theft, or attempts to change established business processes. A convincing video does not need to defeat a technical control if it persuades an employee to bypass one.
Training remains one part of the response, but organisational resilience increasingly depends on what happens after a user makes a mistake. Strong authentication, constrained privileges, independent approval processes, and reliable incident reporting can reduce the consequences of a successful deception even where the initial lure is convincing.
European regulation is also moving towards demonstrable risk management rather than assumptions that individual users will recognise every threat. Financial organisations are already operating under DORA, NIS2 has raised governance and incident-management expectations across essential and important entities, and staged Cyber Resilience Act obligations are extending product-security accountability.
Those regimes address different parts of the technology environment, but each places more emphasis on repeatable organisational controls and evidence that security risks are being managed.
The Eurobarometer results reinforce why that shift is occurring. Phishing remains routine despite years of awareness programmes, while AI-assisted deception is entering the same workplace environment before many employees are confident they can recognise synthetic content.
The survey does not measure whether organisations have the technical and procedural controls needed to contain those failures. It does show that the human layer remains a frequent point of contact between attackers and European organisations even as the surrounding technology becomes more sophisticated.





