Explanation
In this case, the attackers target POST customers. They claim that the recipient paid an invoice twice.
This way, the attackers want to bait the user into clicking on the malicious Rembourser maintenant button which redirects to the phishing form.
Note that the FROM header looks legitimate (contact@post.lu), and a CC header (contact@post.lu) is included. Both headers are spoofed in order to make the message more believable.