The Information Security Team recently ran a phishing simulation across the BALFIN Group to raise awareness about the risks that suspicious emails can bring in our daily work.
This test was designed to check how careful and vigilant we are at spotting potential threats. During the simulation, some colleagues fell for the scenario and entered their credentials on a fake website. The email promised an “End of the Year Gift”, but let’s be clear, it was not a gift. It was phishing!

Why This Matters
Phishing emails are one of the easiest ways attackers can access internal systems. All it takes is one careless click. These emails often mimic the style, tone, and urgency of real company messages, making them tricky to spot if we’re distracted or busy.
The test showed that anyone can fall for a convincing trap, especially when caught off guard.
What You Should Do
- Always check the sender’s email address – don’t rely only on the name.
- Look out for fake domains – for example, @balfin.live instead of the official @balfin.al.
- Pay attention to system warnings – Outlook often flags emails from outside the organization. Real HR emails will never trigger this banner.
- Report suspicious emails immediately to the Information Security Team.
Key Takeaway
This was just a safe simulation, but next time it could be real. Stay alert, question unexpected messages, and always double-check before you click.
Cybersecurity starts with each of us.