Explanation
In this case, threat actors are using a Foyer.lu phishing theme to collect credit card credentials.
The phishing e-mail lures a potential victim to believe a Foyer.lu invoice has been debited by mistake, and a reimbursement can take place clicking on the link.
By clicking on the link, a first basic page that asks the victim name and date of birth is presented.
Once that information is provided, the web page redirects the victim to a fake credit card form.
Note that both, the link and the sender of the e-mail, are unrelated to Foyer.lu.
Example