Three in four EU workers face suspicious emails and links, report finds
Phishing remains the most common cyber threat — only one in two respondents say they are able to spot a deepfake video.
A Eurobarometer survey published by the European Commission on September 30th reveals that three-quarters of workers in the European Union have encountered suspicious emails, messages or links while at work. The Hellenic Data Protection Authority (HDPA) has seized on these figures, released as European Cybersecurity Month began, to emphasize the importance of data protection for both public bodies and private companies.
The survey indicates that cyberthreats have become an integral part of daily work life, and there is a notable discrepancy between employees' knowledge of digital risks and their actual practices. Phishing is the most prevalent threat, with 39% of employees reporting receipt of fraudulent messages or being directed to fake websites aimed at stealing data or gaining unauthorized access. Personal data theft follows closely at 18%, malware attacks at 17%, and password theft at 16%.
Moreover, 15% of respondents have experienced scams powered by artificial intelligence (AI), a category that is becoming increasingly significant due to AI's ability to create convincing messages, images, voices, and videos. While employees are aware of the risks, merely understanding the dangers does not guarantee safe behavior. Eighty-three percent of workers believe a cyberattack can have severe consequences, and 72% claim they can identify suspicious emails. However, only 54% check the sender before clicking on a link.
One of the key concerns identified is the growing challenge of recognizing deepfake videos, with less than half (48%) of employees confident in their ability to spot such manipulated content. Beyond technical solutions, the HDPA is emphasizing the importance of organizations adhering to their legal obligations under Article 33 of the General Data Protection Regulation (GDPR), which requires them to notify the relevant supervisory authority in the event of a data breach. In some cases, they must also inform the individuals whose data has been compromised.
Article 34 of the GDPR mandates that organizations notify affected individuals without undue delay when a breach is likely to significantly impact their rights and freedoms. This notification is vital, as it allows individuals to take protective measures, such as changing passwords, canceling bank cards, and safeguarding themselves against potential financial fraud or identity theft.
Transparency is not only a legal requirement under the GDPR but also plays a crucial role in managing the aftermath of a cyberattack. By promptly informing those affected, organizations can help them take necessary precautions to mitigate potential harm. Furthermore, transparency fosters trust between organizations and the citizens, customers, or employees whose data they handle.
The HDPA urges public bodies and private organizations to conduct a thorough assessment of their readiness for cybersecurity incidents. This involves updating incident response plans, providing regular staff training, and integrating data protection measures at every stage of handling a cybersecurity incident. With three-quarters of EU workers already exposed to suspicious emails and links, the HDPA stresses that cybersecurity is not merely a technical concern but a daily responsibility for all organizations and a fundamental aspect of safeguarding the public.
Written by urgent.news from Euronews's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.