Gen Z Most Vulnerable to Phishing Attacks, Global Study Finds

Abstract digital illustration of a pen writing on a digital surface.

New research has revealed that Generation Z (Gen Z) shows the highest vulnerability to phishing attacks among all age demographics, with 62 percent likely to fall victim to such scams, according to a global survey conducted by Yubico, a leading provider of hardware security keys, spanning 18,000 employed adults across nine countries.

The increased susceptibility stems from several key factors, including Gen Z’s extensive digital engagement and tendency to interact with content quickly without thorough verification. Their password management practices, which often involve reusing credentials across multiple accounts and mixing personal and professional login information, further compound the risk. Such behavior persists despite the growing availability of more secure authentication methods like FIDO2 passkeys, which major technology companies have been promoting as a replacement for traditional passwords.

The study identified polyworking – the practice of maintaining multiple jobs and digital platforms simultaneously – as another significant risk factor, as it expands the potential attack surface for cybercriminals. Additionally, emerging phishing techniques such as “quishing” (QR code phishing) and AI-generated deceptive emails present increasingly sophisticated challenges. Recent research has documented a 26 percent surge in mobile phishing attacks, with QR code-based scams becoming particularly prevalent.

“Our survey revealed a disconnect. Individuals are complacent about securing their own online accounts, and organizations appear slow to adopt security best practices,” said Ronnie Manning, Chief Brand Advocate at Yubico. “It’s not surprising that phishing continues to be one of the easiest ways for hackers to get in.”

Complementary research from the National Cybersecurity Alliance and CybSafe indicates that 59 percent of Gen Z members have experienced losses from various scams, including phishing and cryptocurrency fraud, marking the highest rate among all surveyed age groups. These findings match broader concerns about AI-powered fraud and sophisticated social engineering attacks targeting digital natives.

“People are embracing AI in their personal and professional lives faster than they are being educated on its risks,” said Lisa Plaggemier, Executive Director of the National Cybersecurity Alliance. “Without urgent action to close this gap, millions are at risk of falling victim to AI-enabled scams, impersonation, and data breaches.”

Security experts recommend multiple protective measures, including broader implementation of multi-factor authentication (MFA), passkeys, and hardware security keys as alternatives to traditional passwords. Additional recommendations encompass regular cybersecurity training focused on social engineering awareness, enhanced organizational security policies, and targeted education about emerging phishing vectors. These measures support recent initiatives by major platforms like Google, which has urged its 2.5 billion Gmail users to transition to passkeys.

“Cybercrime is no longer just an occasional risk; it’s becoming a routine experience particularly for younger generations who are deeply immersed in digital life,” said CybSafe CEO Oz Alashe.

Sources: TechJuice, SecurityBrief, GlobeNewswire