> 150.000 m³ concrete poured
We adhere to all protocols
Across Germany and Sweden
You clicked a link in a simulated phishing email.
Your computer is safe and no data has been compromised. This exercise is part of our ongoing security awareness programme. Please take a few minutes to read the information below — it could prevent a real incident.
The email appeared to come from Stark, a well-known construction and building materials supplier active across Northern Europe.
It claimed that an outstanding invoice (#STK-89210) required urgent attention and that updated payment details needed to be confirmed before end of day. A link was provided to "view" the invoice and updated IBAN.
This is a classic Business Email Compromise (BEC) attack — one of the most financially damaging forms of phishing in use today.
Attackers impersonate a plausible vendor, create a sense of urgency around a financial transaction, and direct the target to click a link before they have time to verify the request through another channel.
Every simulated phishing email we send contains observable warning signs. Here are the ones embedded in this message:
| What to look at | What the email showed | Why it is suspicious |
|---|---|---|
| Sender domain | jens.moller.stark.dk@pm.me | The email was sent from a free ProtonMail account, not from a Stark corporate domain. Stark's real domain is stark.dk or stark.de.Any email from an accounts manager at a major supplier arriving from a free webmail service should be treated with immediate suspicion. |
| Signature email | accounts@stark-group-finance.com | The email address shown in the signature is different from the actual sending address, and is itself a look-alike domain. Attackers include a plausible-looking corporate address in the signature to create an impression of legitimacy. |
| Artificial urgency | "Action Required Before End of Day" | Creating a tight deadline is a deliberate tactic to prevent you from pausing to verify the request through another channel. |
| Suspicious link | A hyperlink to "view the invoice" | Legitimate invoices usually arrive as PDF attachments. A link to an external site to "view" payment details is a strong indicator of credential harvesting or malware delivery. |
Many people believe that as long as they do not type their password into a fake website, they are safe. This is no longer true.
Here is what a real attacker could have achieved the moment you clicked:
If you receive an email you suspect is phishing, use the built-in Report Phishing button in Outlook.
This immediately alerts the IT Security team and helps protect your colleagues.
© 2025 BENBAU Management GmbH – All Rights Reserved.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |