Knowledge base › Phishing

Dangers of phishing for businesses

Last updated

A phishing attack is rarely an isolated incident. The dangers extend well beyond a hacked account: financial losses, data breaches, reputational damage and legal consequences can impact a business for months or longer.

1. Financial losses: from fraud to ransomware

The most immediate cost is financial. Phishing leads to three types of financial loss:

Direct fraud

CEO fraud and fake invoices lead to direct transfers to criminal bank accounts. The Dutch Fraud Helpdesk recorded 327 reports of CEO fraud in 2025 (Terugblik 2025). Recovery is rarely possible.

Ransomware

Ransomware infections often begin with a phishing email. Once an employee opens an infected attachment, ransomware encrypts all files on the network. Ransom demands range from thousands to hundreds of thousands of euros. Recovery costs typically exceed the ransom itself.

Operational downtime

A successful attack brings systems down. Work it out for your own situation: a company of 50 employees down for two weeks loses roughly 500 working days of productivity. Lost revenue, overflow costs and recovery work come on top of that.

Figure: Phishing is the most common initial access route in data breaches: 17% of all incidents start with it (IBM, Cost of a Data Breach 2026). The human factor plays a role in 62% of breaches (Verizon DBIR 2026).

2. Data breaches and privacy violations

One of the most serious consequences of phishing is access to confidential data. Via a hacked email account, an attacker gains access to customer data, contracts, personnel files, financial reports and strategic plans.

When phishing targets Microsoft 365 or Google Workspace accounts, the entire mailbox is read, sometimes for weeks, before the attacker acts. During that time, they collect all the information needed for a follow-up attack or to sell on.

Types of data leaked via phishing:

  • Customer data (names, addresses, contacts, contracts)
  • Personnel data (salaries, national ID numbers, medical information)
  • Financial information (bank details, annual reports, debtors)
  • Intellectual property (designs, source code, business strategies)
  • Login credentials for other systems (domino effect)

3. Reputational damage and loss of clients

Reputational damage is the danger of phishing that is hardest to quantify in euros, but can have the heaviest long-term impact. When clients, partners or the media learn that your company has fallen victim to a phishing attack, questions arise about your organisation's reliability and security posture.

Client loss

Clients whose data has been leaked switch to a competitor. In B2B relationships this loss can be lasting, particularly in sectors like finance, healthcare and legal.

Media coverage

Larger incidents make the news. Negative coverage is difficult to neutralise and remains searchable online for years.

Partner confidence

Business partners increasingly ask about your cybersecurity policy. An incident can lead to lost contracts or stricter requirements.

4. Legal consequences and GDPR fines

When a phishing attack leads to a data breach involving personal data, you are required to report this to the relevant Data Protection Authority within 72 hours of discovery. In many cases, affected individuals must also be notified.

GDPR fines

The GDPR requires organisations to take adequate security measures. If an investigation finds that you failed to take sufficient precautions, including employee awareness training, the supervisory authority can impose fines of up to €20 million or 4% of annual global turnover.

NIS2 Directive

The NIS2 Directive requires organisations in essential sectors and their suppliers to implement proven measures against cyber attacks, including demonstrable security training for employees. Phishing simulations and awareness training are a direct way to satisfy this requirement.

Liability towards third parties

If your compromised systems are used to attack clients or partners, you can be held liable for the damage those third parties suffer as a result. This is an underestimated but very real legal risk.

How to limit the dangers of phishing

The dangers of phishing are real but largely manageable. The most effective approach combines technical measures with human training:

  • Multi-factor authentication (MFA) on all accounts
  • Email authentication: SPF, DKIM and DMARC to block spoofed senders
  • Regular phishing simulations to identify vulnerable employees
  • Security awareness training so employees recognise phishing
  • A clear reporting procedure for suspicious emails
  • An incident response plan so you know what to do if an attack succeeds