The "Seat-Agreement VIP discount" was not real. It was a controlled security awareness exercise run by CEDEFOP IT to help everyone recognise the real thing.
It used something true about you, your real VAT and tax entitlements under the seat agreement, as bait. Attackers love real, familiar details because they lower your guard. A genuine entitlement never has to be "unlocked" by typing your work password into a link from an email.
The email carried a copied CEDEFOP logo, but a logo proves nothing. What matters is the sending domain, which was an outside lookalike, not an official CEDEFOP address.
"First 150 only" and "closes 30 October" exist to make you act before you think.
Roughly 50% off everywhere, forever, bundled across travel, shopping and dining. Real programmes are rarely this generous or this broad.
The key trap. Your seat-agreement status is not confirmed by entering your CEDEFOP password on an outside site. Any link asking for your work login to "verify entitlement" is suspect.
"Dear valued colleague", with no name, because it was sent to many people at once.
Hovering the button revealed a destination unrelated to any official CEDEFOP or partner site.
Stop. Hover. Report.
Thank you for taking part in this security awareness exercise. A short security awareness training session will follow soon. You will receive a separate notification with all the details and instructions when it becomes available.