Explanation
Threat actors are using a Foyer.lu phishing theme to collect credit card information.
The phishing e-mail lures a potential victim to believe that he paid too much for a Foyer.lu invoice, and a reimbursement can take place clicking on the link.
This is especially dangerous for Foyer.lu clients.
When clicking on the link, a first page asks for the victim name and date of birth.
Once that information is provided, the web page redirects the victim to a fake credit card form.
Finally, the victim is redirected to a fake Luxtrust phishing page, where the ultimate goal is to collect Luxtrust token one-time-passwords and credentials.
Note that both the link, and the sender of the e-mail are unrelated to Foyer.lu.
Example