> 150.000 m³ concrete poured

We adhere to all protocols

Across Germany and Sweden

IT Security Department

Security Awareness Training

This was a simulated phishing test.

You clicked a link in a simulated phishing email.

Your computer is safe and no data has been compromised. This exercise is part of our ongoing security awareness programme. Please take a few minutes to read the information below — it could prevent a real incident.

About the email you received

The email appeared to come from Stark, a well-known construction and building materials supplier active across Northern Europe.

It claimed that an outstanding invoice (#STK-89210) required urgent attention and that updated payment details needed to be confirmed before end of day. A link was provided to "view" the invoice and updated IBAN.

This is a classic Business Email Compromise (BEC) attack — one of the most financially damaging forms of phishing in use today.

Attackers impersonate a plausible vendor, create a sense of urgency around a financial transaction, and direct the target to click a link before they have time to verify the request through another channel.

Red flags that were present in the email

Every simulated phishing email we send contains observable warning signs. Here are the ones embedded in this message:

What to look atWhat the email showedWhy it is suspicious
Sender domainjens.moller.stark.dk@pm.meThe email was sent from a free ProtonMail account, not from a Stark corporate domain. Stark's real domain is stark.dk or stark.de.

Any email from an accounts manager at a major supplier arriving from a free webmail service should be treated with immediate suspicion.
Signature emailaccounts@stark-group-finance.comThe email address shown in the signature is different from the actual sending address, and is itself a look-alike domain.

Attackers include a plausible-looking corporate address in the signature to create an impression of legitimacy.
Artificial urgency"Action Required Before End of Day"Creating a tight deadline is a deliberate tactic to prevent you from pausing to verify the request through another channel.
Suspicious linkA hyperlink to "view the invoice"Legitimate invoices usually arrive as PDF attachments.

A link to an external site to "view" payment details is a strong indicator of credential harvesting or malware delivery.

Why clicking a link is enough in 2026

Many people believe that as long as they do not type their password into a fake website, they are safe. This is no longer true.

Here is what a real attacker could have achieved the moment you clicked:

1. Drive-by Download Simply visiting a compromised or attacker-controlled website can silently install malware on your device — no further interaction required.

Attackers exploit unpatched vulnerabilities in browsers or plugins to execute code the moment the page loads.
2. Session Token Theft (Adversary-in-the-Middle) Even with Multi-Factor Authentication (MFA) enabled, attackers can intercept your active session token.

This means they gain access to your Microsoft 365 account — email, Teams, SharePoint — without ever knowing your password.
3. Device Code Abuse A growing technique involves prompting you to enter a short code on the legitimate Microsoft login page.

Doing so unknowingly authorises the attacker's device to access your account, bypassing MFA entirely.

How to report a suspicious email in Outlook

If you receive an email you suspect is phishing, use the built-in Report Phishing button in Outlook.

This immediately alerts the IT Security team and helps protect your colleagues.