Phishing: Increasing frequency and sophistication In its various forms, phishing has long been the most widespread attacker technique. The majority of survey respondents encountered this threat in 2023 (Fig. 14). More recent forms of phishing, including vishing, smishing and quishing, were frequently mentioned. Distinct phishing types encountered by respondents in 2023 (% of respondents) Phishing 89 % Fraudulent email 82 % Spearphishing 50 % Vishing 15 % 0% 10 % 20 % 30 % 40 % 50 % 60 % 70 % 80 % 90 % 100 % Figure 14 CEO email fraud, where attackers impersonate an organisation’s director to authorise fund transfers, was also identified as a significant threat in 2023. NÚKIB itself was impersonated in a vishing campaign (see section “Financial Sector”). The quality of all types of phishing attacks continues to improve, often appearing more credible and grammatically correct, sometimes displaying detailed knowledge of the victim or organisation. This increase in quality is likely (55–70 %) due to the availability of AI tools and the proliferation of specific phishing tools on the dark web (see section “Cybersecurity trends in the Czech Republic for 2024 and 2025”). 25

Select target paragraph3