Phishing: Increasing frequency
and sophistication
In its various forms, phishing has long been the most widespread attacker technique. The majority of survey respondents encountered this threat in 2023 (Fig.
14). More recent forms of phishing, including vishing, smishing and quishing, were
frequently mentioned.
Distinct phishing types encountered by respondents in 2023
(% of respondents)
Phishing
89 %
Fraudulent email
82 %
Spearphishing
50 %
Vishing
15 %
0%
10 %
20 %
30 %
40 %
50 %
60 %
70 %
80 %
90 %
100 %
Figure 14
CEO email fraud, where attackers impersonate an organisation’s director to authorise
fund transfers, was also identified as a significant threat in 2023.
NÚKIB itself was impersonated in a vishing campaign (see section “Financial Sector”).
The quality of all types of phishing
attacks continues to improve,
often appearing more credible and
grammatically correct, sometimes
displaying detailed knowledge of the
victim or organisation.
This increase in quality is likely
(55–70 %) due to the availability of AI
tools and the proliferation of specific
phishing tools on the dark web (see
section “Cybersecurity trends in the
Czech Republic for 2024 and 2025”).
25