CEDEFOP
● Safe simulation, no harm done

This was a phishing test.

The "Seat-Agreement VIP discount" was not real. It was a controlled security awareness exercise run by CEDEFOP IT to help everyone recognise the real thing.

Nothing bad happened, and this is not about you personally. No account was compromised, no password was captured, and there is no penalty. Results are reported only as anonymous totals. The goal is practice, not blame.

Why this one was clever

It used something true about you, your real VAT and tax entitlements under the seat agreement, as bait. Attackers love real, familiar details because they lower your guard. A genuine entitlement never has to be "unlocked" by typing your work password into a link from an email.

What gave it away

Six signs in this email

1

An external sender, even with our logo

The email carried a copied CEDEFOP logo, but a logo proves nothing. What matters is the sending domain, which was an outside lookalike, not an official CEDEFOP address.

2

Urgency and scarcity

"First 150 only" and "closes 30 October" exist to make you act before you think.

3

Too good to be true

Roughly 50% off everywhere, forever, bundled across travel, shopping and dining. Real programmes are rarely this generous or this broad.

4

It asked you to verify with your work account

The key trap. Your seat-agreement status is not confirmed by entering your CEDEFOP password on an outside site. Any link asking for your work login to "verify entitlement" is suspect.

5

A generic greeting

"Dear valued colleague", with no name, because it was sent to many people at once.

6

The link did not match

Hovering the button revealed a destination unrelated to any official CEDEFOP or partner site.

The one habit that beats all of this

Stop. Hover. Report.

Stop, pressure and "act now" are the warning, not the reason to hurry.
Hover, rest on any link and read where it really goes before clicking.
Report, if anything feels off, use the Report button in Outlook:
⚑ Report Phishing
Questions? Contact the IT Service Desk.
CEDEFOP, Information Security & Awareness Programme. This exercise complies with the agency's EUDPR data-protection record.