Explanation
In this case, customers of the bank Société Générale are targeted.
The phishing mail leads the user to believe that a new important security document is available, and by clicking on the link the user is redirected to the phishing landing page.
After clicking, the landing page presents a fake notice that claims the user must activate strong authentication for his account to be compliant with the payment services (PSD 2) directive (EU) 2015/2366.
In order to “activate” those security services, the user has to click on the link ‘PASS-SECURITE’, where they will then be asked to enter their account information.
Note that neither the phishing mail nor the landing page are in any way linked to Société Générale.
Example