Phishing is up 70.6% in Romania — what that means for your simulation programme

Phishing is up 70.6% in Romania — what that means for your simulation programme

The Romanian National Cyber Security Directorate (DNSC) published its 2025 activity report, approved by CSAT Decision no. 117 of 7 August 2026. One figure in it should reshape how Romanian organisations run security awareness: 4,975 phishing incidents, up 70.6% on 2024, with phishing named the primary attack vector of the year.

Read that number next to the one immediately below it in the same report and the picture sharpens. Brute-force incidents fell 72.7%, from 172 to 47. DDoS incidents fell 52.8%. Over the same period, account compromise rose 353% — from 248 incidents to 1,125 — and fraud or attempted fraud rose 91%, from 2,061 to 3,937.

The controls that block machines attacking machines are holding. Account lockout, rate limiting, reduced exposure of RDP and admin interfaces: these have measurably worked in Romania over the last two years. The controls that are supposed to stop a person being convinced to do something are not keeping pace. That is a resourcing signal, and most awareness programmes have not responded to it.

What the attacks actually look like now

DNSC is specific about why phishing grew, and each reason has a direct consequence for how you simulate it.

Campaigns have been professionalised. The era of the obviously machine-translated Romanian message is over. Messages are correctly written and reproduce the visual identity of legitimate institutions and companies faithfully. If your simulation templates still contain deliberate spelling errors as a difficulty dial, you are testing for a signal that no longer appears in real attacks.

Delivery is multi-channel. DNSC attributes part of the growth to campaigns that combine email with messaging apps and social platforms. The 353% rise in account compromise is linked specifically to social engineering over WhatsApp — including the "vote for my daughter in a competition" pattern — followed by redirection to fraudulent pages or requests for authentication codes. A programme that only sends emails is measuring one channel of a three-channel attack.

AI is in the attack chain. The report cites widespread use of AI mechanisms both in the lures themselves and in attack preparation. Fraud growth is additionally linked to telephone spoofing, which pairs naturally with voice cloning.

Targeting is sectoral and predictable. Banking, postal and courier services, and financial market infrastructure together accounted for 3,326 incidents — 88.23% of all reports. If you are in one of those sectors, or you serve them, your staff see impersonation of those brands constantly. If you are not, your staff still see them, because they bank and receive parcels like everyone else.

Four things to change in your programme

Frequency, and what happens between rounds. An annual simulation produces an annual number and no behaviour change. Continuous, randomised delivery across the year is what generates a stable baseline and reveals whether reporting behaviour improves. The point is not to catch more people; it is to shorten the gap between an employee seeing something odd and someone in the organisation knowing about it.

Local scenarios, not translated ones. A generic template about a package from an unnamed courier is not the attack your people receive. Romanian-language lures impersonating Romanian banks, Fan Courier or Sameday delivery notices, ANAF and SPV notifications, invoices with Romanian VAT formatting, and messages that arrive in the days around a real tax deadline are what land. Add the channels that DNSC flagged: WhatsApp messages from a number claiming to be a colleague or a manager, and a callback number that leads to a vishing script. Our phishing simulation programme is built around scenarios drawn from what is actually circulating in Romania, not a global template library.

Measure past the click rate. Click rate is the metric that flatters programmes and predicts nothing. Four measurements tell you more:

  • Report rate, and the ratio of reports to clicks. An organisation where 40% click and 60% report is in a better position than one where 10% click and nobody reports.
  • Time to first report, measured in minutes from delivery. This is your real detection latency for a campaign nobody else caught.
  • Credential submission rate, which is different from click rate and much closer to what an attacker needs. Given the 353% rise in account compromise, submission of a one-time code should be tracked separately.
  • Repeat-click concentration. A small group usually accounts for a disproportionate share. That is a targeted-coaching problem, not an all-staff-training problem.

Measure the organisation, not the individual. A programme perceived as a trap for catching employees stops producing reports, which destroys the only metric that matters.

Cover phishing-resistant authentication properly. Account compromise grew four and a half times, and DNSC links it to password reuse, missing or poorly configured MFA, and credential stuffing. Awareness that stops at "don't reuse passwords" is a decade behind. Staff need to recognise MFA fatigue prompts, understand that a legitimate service never asks for a code by phone or chat, and know what a device-code or OAuth consent prompt looks like when it is being abused. That belongs in awareness and training content, and the underlying identity controls belong in your risk assessment.

Documenting it for a DNSC inspection

Romania transposed NIS 2 through OUG 155/2024, in force since 30 December 2024 and amended by Law 124/2025. Two consequences matter for awareness programmes at essential and important entities.

First, the management body approves cyber risk management measures, oversees their implementation and bears responsibility for breaches of those obligations — and Law 124/2025 added an explicit obligation of periodic training for the management body itself. Executive training is no longer a nice-to-have that gets scheduled and then cancelled.

Second, awareness and cyber hygiene training is a named risk-management measure, not a discretionary extra. Under supervision, the difference between an entity that complies and one that does not is almost always evidence. What to keep, from the start rather than the week before an inspection:

  • Attendance and completion records per person and per role, with dates.
  • Evidence that the management body received training, distinct from staff training.
  • The simulation programme plan: frequency, scenario categories, target populations, approval.
  • Results per round with trend over time, and the remediation actions triggered — not only the metrics.
  • Whoever approved the programme and when, and the link to the risk assessment that justified it.

If you are building this from nothing, treat it as one workstream with your broader audit and compliance work rather than a separate training project, and place it inside a measured human risk management programme so the numbers connect to the risk register.

The honest reading of the figures

DNSC's sensors also recorded 7,251,708 attempts associated with phishing campaigns during 2025, against 941,076 in 2024. Almost all of them stopped at a filter. The 4,975 that became incidents are the residue — the ones that got through the technology and reached a person who acted on them.

You cannot filter your way out of a 70.6% increase. You also cannot train your way out of it. What the national numbers argue for is the same discipline already applied to brute force: continuous measurement, controls sized to the actual threat, and evidence that the measures are in place. The brute-force line in next year's report will probably fall again. Whether the phishing line does depends on decisions made this year.

This article is general information, not legal or regulatory advice. Confirm your specific obligations with DNSC guidance and qualified counsel.

Sources: DNSC 2025 activity report coverage, Income Magazine; DNSC; Economedia. Figures are as reported from the DNSC activity report for 2025 approved by CSAT Decision no. 117 of 7 August 2026; the report's own methodology for classifying incidents applies.

Back to blog