Explanation
Threat actors are using a Foyer.lu phishing theme to collect personal information, credit card information and Luxtrust OTP codes.
The phishing e-mail lures a potential victim to believe a Foyer.lu invoice has been debited by mistake, and a reimbursement can take place clicking on the link. Notice that the URL shown in the email is just a label, but the actual link points to the landing page.
When clicking on the link https://ssowebauth.lefoyer.lu, a first page asking for personal information, such as name and date of birth, is presented.
Once that information is provided, the victim is redirected to a fake credit card form. After which the victim is finally redirected to a fake Luxtrust phishing page, where the ultimate goal is to collect Luxtrust token one-time-passwords.
Note that both the link, and the sender of the e-mail are unrelated to Foyer.lu.
Example