In 2025, the Latvian Cyber Incident Prevention Institution CERT.LV conducted 16 campaigns simulating phishing attacks. Their aim was to test the vigilance of employees in enterprises and determine which areas required additional cybersecurity training measures. A total of 15,436 emails were sent as part of the checks. Recipients opened 4,859 of them, or 31.48%. An even more striking result was that in 3,032 cases, users entered authentication data after opening the email. During the simulations, it was tested whether it would be possible to obtain protected information — such as email addresses, usernames, or passwords — as well as to get the recipient to download an attachment and run a potentially malicious file on their computer. After each campaign, the organization received a report on the results and recommendations for improving security. **Phishing Emails Are Still Difficult to Recognize** CERT.LV notes that a significant portion of users still struggles to distinguish between legitimate emails and phishing emails sent by malicious actors. Therefore, the organization recommends that institutions and enterprises regularly train employees to recognize such threats. During the checks, specialists discovered various issues — from SQL injections and XSS vulnerabilities to the ability to access other users' emails and uploaded files without necessary authorization. Particularly serious deficiencies were identified in e-commerce: in some cases, it was possible to alter the prices of goods and delivery and even bypass the payment process. CERT.LV is a structural unit of the Institute of Mathematics and Computer Science at the University of Latvia. Its tasks include assisting in the prevention and coordination of the resolution of information security incidents in the Latvian segment of the internet.