The question comes up in most scoping conversations with a European client. It usually arrives with an answer already attached. European staff are assumed to be harder targets. Eight years of GDPR have made them privacy-literate. Business correspondence is more formal. People are less inclined to act on an unexpected instruction from someone claiming authority.
The intuition is reasonable. The evidence does not support it.
That matters more than it first appears, because the belief is load-bearing. It shapes how much a European organisation spends on awareness, which controls it buys, and whose evidence it accepts when a vendor says a programme works. If the premise is wrong, the decisions resting on it inherit the error.
The accurate answer is more useful than either yes or no. Region does not predict who falls for a lure. It predicts three other things: what an attacker can borrow to make a lure credible, who is aiming at your organisation and why, and whether a control you have bought has any evidence behind it in your population.
What the evidence says about culture
The most direct test of the cultural question was published this July. Junger and seventeen co-authors, led from the University of Twente, ran a cross-cultural experiment with 2,143 participants across twelve countries in Asia, Africa, North America and Europe, analysed with signal detection theory and mixed modelling.
The result was a null. Phishing victimisation was significantly associated with low self-control, high risk-taking, high exposure and poorer recognition of legitimate email. Cultural orientations, religiosity and country of origin had minimal effects. The authors put it plainly: for culturally diverse organisations, cultural factors may be less critical to phishing victimisation than has previously been assumed.
Two caveats belong with that figure. The sample is university students rather than employees, and victimisation was self-reported. It is not the final word. But it is the largest and most recent test of the specific proposition that nationality predicts who gets phished. It finds no such effect.
That result is also consistent with what came before. A 2024 study of 449 people in Portugal found that the majority of individual and contextual factors tested predicted nothing at all. The two that did were counter-intuitive: heavier routine internet use, and believing you are good at spotting phishing. Confidence made people more susceptible, not less. That echoes an earlier finding of ours: seniors clicked most and were the least likely to believe they would.
Step back across the literature and the pattern is not subtle. Researchers have been looking for the person who falls for phishing for the better part of two decades and keep returning weak, contradictory or null results. Age is the clearest example. Some studies find seniors more resilient, others find them markedly more vulnerable. The disagreement tracks methodology rather than population. If demographics and culture reliably predicted victimisation, that much looking would have found it.
So the honest answer to the opening question is no, with one qualification. Nothing about being European makes a person harder to deceive. Plenty about being in Europe changes the attack that arrives.
One dataset, both regions
Most regional comparisons fail before they start, because they set two different instruments side by side and read the difference as a fact about the world. One source measures both regions the same way, and repays a close reading.
The 2026 Verizon Data Breach Investigations Report includes a regional breakdown with 6,060 breaches in its EMEA dataset. Phishing appears in 84 per cent of social-engineering-related breaches in EMEA, against 69 per cent across the full dataset. That is a real gap, measured with one instrument. The direction it points is not the one the intuition expects.
| Verizon DBIR 2026 | EMEA (n=6,060) | Full dataset |
|---|---|---|
| Phishing, as a share of social-engineering-related breaches | 84% | 69% |
| State-affiliated actors involved | 23% | 14% |
| Espionage-motivated breaches | 27% | 13% |
The three figures move together, which is the whole finding. Verizon draws the connection itself, noting that the phishing share lines up with the region’s higher proportion of state-affiliated actors. Germany’s federal cybersecurity agency reports the same shape from national data: public administration was a principal target of cyberespionage, and by far the largest number of Germany-relevant APT groups aimed at that sector.
So European organisations do see proportionally more phishing. Not because European staff are softer, but because a greater share of the adversaries pointed at them are running espionage rather than commodity fraud, and for an espionage operator phishing is the cheapest reliable route to one named person inside a specific building.
Two limits belong on that reading. EMEA is Europe, the Middle East and Africa. The espionage skew is not purely European. And Verizon states in the same section that its dataset carries a built-in tilt toward North America, driven by where its contributors are based. Neither undermines the finding. Both should stop anyone treating the percentages as precise.
Compare like with like and the picture converges
The strongest evidence that regional difference is overstated comes from putting the two law-enforcement views next to each other.
Europol’s 2026 organised crime threat assessment calls fraud schemes the fastest-growing area of organised crime in the EU, and lists the typologies its member states report most often.
The FBI’s 2025 internet crime report records more than 20 billion dollars in reported losses, ranked by category. Phishing and spoofing generate the highest complaint count of any type at 191,561.
| Europol IOCTA 2026 (EU) | FBI IC3 2025 (US) |
|---|---|
| Investment fraud, especially crypto | Investment fraud (largest by reported loss) |
| Business email compromise | Business email compromise |
| Romance fraud | Tech support scams |
| Tech support fraud | — |
| Fraud against payment systems | — |
The two lists are not built on the same basis. Europol records the types its member states report most often; the FBI ranks by reported loss. That mismatch makes the overlap more striking rather than less.
Two independent law-enforcement instruments, two continents, effectively the same answer. The crimes that take the most money from people in Europe are the crimes that take the most money from people in the United States.
This is where most published regional comparison goes wrong. The EU’s flagship technical assessment, ENISA’s threat landscape, measures organisational intrusion vectors and finds phishing at about 60 per cent. The FBI’s report measures citizen-reported financial loss. Set those two numbers beside each other and you can manufacture almost any regional story you like, because they do not count the same events, the same victims or the same denominator. We have used both figures ourselves. The ENISA share sits behind how a Lockdown investigation runs. The IC3 total appears next to the Pew finding that only 26 per cent of Americans who lose money to an online scam report it to anyone official, which makes the reported number a floor rather than a measurement.
The practical implication is unglamorous. Before accepting any claim that a region behaves differently, check whether the two figures came from the same instrument. Most of the time they did not. The difference belongs to the measurement rather than to the crime.
What is genuinely local: the props
Persuasion is universal. Authority works on everyone. So does urgency, and so does the reluctance to challenge someone further up the hierarchy. Which of those levers works on whom is its own body of evidence: scarcity and authority outperform social proof by a wide margin.
What is local is not the lever. It is the costume.
Authority is only persuasive if the authority is one the target recognises and fears in the right proportion. An American employee has a working model of what a message from the tax authority looks like, what a bank fraud team sounds like on the phone, and which regulator would plausibly contact their employer. A Dutch or German employee has an equally strong model, built from entirely different institutions. The lever is the same. The props are not interchangeable.
Europol’s assessment is explicit that this is where generative AI has changed the economics, describing AI-assisted impersonation of bank helpdesk and law enforcement personnel as a live technique. France’s national agency reports the same category of work from the other direction. Through 2025 ANSSI observed SIM-swapping, MFA fatigue, identity theft and vishing in cybercriminal operations, along with tech support scams that talked employees into installing remote management tools, which the attackers then used to sidestep firewall rules and evade endpoint detection.
The props an attacker needs are ordinary and specific: which tax body writes to people, which bank the company uses, which regulator has standing, whether an internal request would come from HR or from a works council, who signs off a payment and who covers when they are away. None of this is secret. Most of it is assembled from public filings, supplier announcements, staff profiles and the ordinary exhaust of doing business in a particular country.
That is the part a European organisation can actually change. It is also the part almost nobody audits.
The props an attacker needs are published, and most organisations have never looked at what theirs would be.
Assess organisational exposureLocalisation is now a product feature
There used to be a friction that protected non-English markets. An attacker had to learn your language, your institutions and your business conventions well enough to be plausible, and for most targets that was not worth the effort.
That friction is gone. It did not disappear gradually.
ENISA’s 2025 threat landscape documents phishing-as-a-service platforms that industrialise exactly this work. The Darcula platform was seen impersonating more than 200 organisations, reaching victims in more than a hundred countries. Another, Lucid, ran campaigns through iMessage and RCS against 169 targets across 88 countries. A third, FlowerStorm, is an adversary-in-the-middle kit that mimics Microsoft 365 portals and defeats multi-factor authentication. Alongside them ENISA records fake CAPTCHA lures that talk users into running PowerShell commands themselves, a campaign that infected 9,300 sites through compromised WordPress installations, and QR codes embedded in PDF attachments to get past mail filtering.
Europol describes the commercial side of the same shift, noting that advertising on very large online platforms lets criminal networks industrialise targeting and bypass geographic and linguistic barriers.
The local prop is no longer bespoke attacker effort. Today it ships as a template in a kit sold by subscription. Any defensive assumption resting on the idea that a foreign operator will not bother to localise for your market has quietly expired. The organisations most exposed are the ones that never made that assumption explicit enough to notice it failing.
Where region actually bites: the defence
Here is the finding that should change what a European security team buys.
Waldo Rocha Flores and colleagues studied 2,099 employees across nine organisations in Sweden, the United States and India, using scenario-based surveys validated against unannounced phishing experiments on the same people. Their conclusion was that national culture has a significant effect on behavioural information security and on the determinants of employees’ social engineering security behaviour.
Read quickly, that looks like a contradiction of the Junger result. It is not.
Junger measured who ends up a victim, and found culture barely matters. Flores measured which factors predict behaviour, and found culture matters a great deal. Both can be true, because they are different questions. Culture does not change who falls for a lure. It changes which defensive levers actually pull.
A 2025 study in the Journal of Cybersecurity shows the same effect with unusual clarity. Petrič and Just surveyed 1,017 employees in Germany, the United Kingdom and the United States, all in organisations of fifty staff or more, and modelled what drives people to report a phishing email. In Germany, attitudes drove reporting. In the United Kingdom, a sense of personal responsibility did. In the United States neither had strong explanatory power. The model explained 31.6 per cent of reporting behaviour in the UK, 26.0 per cent in the US and 14.5 per cent in Germany.
The most practical number in that study concerns tooling. Providing reporting tools had a clear effect in the UK and the US. In Germany it had none worth reporting. The same control, deployed identically, worked in two countries and did nothing in the third.
This is the real regional finding. Susceptibility never enters into it. A control whose evidence base came from a US workforce is an untested assumption when applied to a German one. That does not disqualify the control. What it demands is knowing which population the evidence came from before treating a vendor’s efficacy claim as applying to your own staff.
We are deliberately not relitigating whether awareness training works. That is a separate question with its own evidence. We have written about what a phishing simulation is really testing. The point here is narrower and less contested: efficacy does not automatically travel.
What actually predicts victimisation
If culture does not predict who falls, and demographics do not, something must.
The Flores work answers it directly. Among the factors that significantly influence whether employees fall victim to social engineering, one stands out for being entirely within an organisation’s control: the amount of information specific to a target organisation included in an attack significantly increases the probability that employees fall victim.
France’s national agency reports the same mechanism from live incidents rather than experiments. Assessing the Scattered Spider intrusion set, which compromised several French entities including firms in the luxury goods sector during 2025, ANSSI attributes the effectiveness of the techniques largely to the attacker’s knowledge of internal company processes and to the reconnaissance phase in which personal data on the targeted employees was collected to prepare the attack. In at least one case the attackers impersonated the IT department to obtain access credentials for a customer relationship management system. We have written separately on how Scattered Spider works.
Put the experimental finding and the incident finding together and the answer points at the attacker’s preparation rather than the victim’s character.
Which brings us back to the most quietly important line in the Junger study. Being able to recognise phishing was unrelated to victimisation. Being able to recognise legitimate email reduced it.
That is worth sitting with, because it inverts how awareness is usually sold. The protective skill is not suspicion. It is calibration: an accurate working model of what real correspondence from your bank, your regulator, your supplier and your own IT department looks like. Suspicion without calibration produces people who hesitate over genuine invoices and still click the good fake.
And calibration is precisely what degrades when an attacker can assemble a message from true details. A lure built from your actual supplier, your actual reporting line, your actual reorganisation and your actual travel dates does not fail a calibration test, because on every checkable dimension it is correct. The defence does not fail because the reader was careless. It fails because the forgery was sourced from reality.
That is the through-line. It is not who your people are. It is what an attacker can learn about them before writing.
What this means in practice
For a European organisation, four things follow.
The regional question is worth asking, but not the way it is usually asked. Stop asking whether your staff are more or less susceptible than an American workforce, because the evidence says the difference is small and you cannot act on it. Ask instead which local institutions an attacker would borrow to reach them.
Take the espionage share seriously if it applies to you. The EMEA phishing skew tracks state-affiliated activity, so an organisation in a sector those actors care about is facing a different attacker with different patience, not a louder version of commodity fraud.
Ask any vendor where their efficacy evidence was gathered. If a control was validated on a US workforce, that does not disqualify it. Put the question in writing before renewal.
Audit the props. The material that makes a lure land is public, specific to your organisation and reducible. Among the factors that decide whether a lure lands, it is the only one you own outright.
A corporate exposure audit maps that material the way an attacker would assemble it: what is published about your people, your suppliers, your reporting lines and your calendar, and which of it makes a forged message pass a calibration test it should fail. The work is diagnostic rather than instructional, and its target is the one factor the evidence consistently identifies.
Sources
Junger, M., Olber, P., Płocki, R., Luyten, H., Koning, L., Muniz, C.N., Bullee, J-W., Wang, V., Botha, R., Howell, C.J., Distler, V., Chen, X., Pham, H.C., Aljohani, M., Richards, N.U., Muhly, F., Abhishta, A., and Furnell, S., “Relationships between cultural orientations, phishing victimization, and phishing recognition: A cross-cultural experiment”, Computers & Security 170, 105050, 2026.
Ribeiro, L., Sousa Guedes, I., and Cardoso, C.S., “Which factors predict susceptibility to phishing? An empirical study”, Computers & Security 136, 103558, 2024.
Rocha Flores, W., Holm, H., Nohlberg, M., and Ekstedt, M., “Investigating personal determinants of phishing and the effect of national culture”, Information and Computer Security 23(2), 178–199, 2015. Findings as stated in Rocha Flores, W., Shaping Information Security Behaviors Related to Social Engineering Attacks, doctoral thesis, KTH Stockholm, 2016.
Petrič, G., and Just, J.N., “Information security culture and phishing-reporting model: structural equivalence across Germany, UK, and USA”, Journal of Cybersecurity 11(1), tyaf011, 2025.
Verizon, 2026 Data Breach Investigations Report, regional analysis, EMEA dataset n=6,060.
Europol, Internet Organised Crime Threat Assessment 2026.
ENISA, Threat Landscape 2025, October 2025.
Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report.
ANSSI / CERT-FR, Cyber Threat Overview 2025, CERTFR-2026-CTI-003.
Bundesamt für Sicherheit in der Informationstechnik, Die Lage der IT-Sicherheit in Deutschland 2025.