Danger on the screen and one click to fraud - How did Ljiljana prevent the company from losing EUR 35,000?
Source: eKapija
Monday, 17.11.2025.
22:09
Monday, 17.11.2025.
22:09
Illustration (Photo: Photosani/shutterstock.com)
But something didn`t give her peace. Maybe just that imposed urgency. And maybe the fact that she`s received in-house cyber security training and knows full well that any email that creates a sense of pressure, panic or urgency needs to be double-checked. She checked. The director didn`t send the email. A serious financial loss was prevented.
Such scenarios have become commonplace today and the best proof that phishing is no longer an amateur message with bad spelling, but a carefully designed scam. Dr. Miloš Jovanović, professor of information security at the University of Kragujevac and president of the OpenLink Group, warns against this, as he points out that today`s attacks are "far more sophisticated and personalized than ever before".
According to him, phishing is no longer a mass fraud sent to thousands of addresses, but an attack aimed at specific people in a specific organization. Instead of generic emails that once easily betrayed a scam, spear phishing attacks, business email compromises, social media scams, as well as SMS and WhatsApp messages that look completely legitimate dominate nowadays.
- Phishing is no longer a mass campaign "for everyone", but a precisely targeted attack against a specific person, function or organization. Today, such attacks often include elements of social engineering, where the user is psychologically manipulated into believing in the authenticity of the communication. In addition, attackers increasingly use generative artificial intelligence in order to create messages without grammatical errors and with a convincing tone, which makes it even more difficult to recognize fraud - our interlocutor explains.
The attackers prepare in detail: they use data gathered from social networks, information from previously compromised databases, imitate the communication style of executives and increasingly apply generative artificial intelligence to create messages, which seem flawless in tone and language. Because of this, says Jovanović, "the line between real and fake messages becomes extremely thin".
In such an environment, recognizing phishing calls for both technical and psychological attention.
- First of all, employees should check the address of the sender, the tone of the message and possible grammatical errors, as well as links leading to suspicious domains. Any message that creates a sense of urgency or pressure ("react immediately", "the account will be blocked") should arouse suspicion - the professor emphasizes.
Every second employee falls for the scam
However, research shows that less than half of employees react correctly in the first seconds of contact with a suspicious message, which, according to Jovanović, clearly shows that education must be continuous and focused on practical simulations, and not on one-time presentations.
When it comes to protection, companies need to build a multi-layered strategy that combines technical tools and employee awareness.
- Technical measures include multi-layered protection, from advanced e-mail filters and DMARC/SPF/DKIM policies, to the introduction of multi-factor authentication (MFA) and controlled access to sensitive resources. At the organizational level, a clear security culture that includes clearly defined procedures, constant education and proactive monitoring of suspicious activities through systems for detection and response to incidents (EDR/SIEM solutions) is key - says the eKapija interlocutor.
The best protection, he emphasizes, is a combination of technology and user awareness, because even the most expensive security system cannot compensate for one wrong click.
- The individual protection of users through passkey systems and biometric authentication, which reduce the risk of password theft and phishing attacks, plays an increasingly important role. Such solutions allow logging in without a classic password, with identity confirmation via fingerprint, facial recognition or security key, which significantly increases the level of personal and corporate security - explains Professor Jovanović.
And what if someone does click?
Dr. Jovanović emphasizes that the speed of the reaction makes the decisive difference.
- In practice, it is not crucial whether someone clicked, but how quickly it is reported and how the organization reacts. If there is a clear channel to report a suspicious event and if the IT team immediately isolates the device, checks the network traffic and informs other users, the harm can be completely prevented, he says
The problem, however, arises when employees remain silent for fear of being blamed. That`s why, he points out, the culture of security transparency must be part of the internal policy, which should mandate that mistakes be reported immediately and without fear of sanctions.
In the long term, businesses need to change the way they think about security.
- It is no longer enough for the IT team to be the only one thinking about protection, but every employee must understand that they are part of the first line of defense. This means that every message, link or request for confidential data is checked without haste and without automatic trust, even if it seems legitimate. Regular, practical training of employees is crucial, but not through dry presentations and "online trainings", but through real examples and trainings that help people learn to recognize suspicious situations in their daily work. And finally, it is important that there is a clear and simple procedure for reporting suspicious messages, without fear of making a mistake, because a quick reaction often makes the difference between minor disturbances and a serious security incident - Professor Jovanović concludes.
Ivana Žikić

Click here to see the entire Special Edition Newsletter
"CLICK TO SUCCESS – Fast. Digital. Smart."
read more
Tags:
University of Kragujevac
OpenLink Group
Miloš Jovanović
cyber security
phishing
how to recognize phishing
how to protect yourself from phishing
special edition newsletter
digitization
special edition newsletter Click to success Fast Digital Smart
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora