Explanation
Threat actors are using a Foyer.lu phishing theme to collect credit cards and Luxtrust credentials.
The phishing e-mail lures a potential victim to believe a Foyer.lu invoice has been debited by mistake, and a reimbursement can take place clicking on the link. This is especially dangerous for Foyer.lu clients. Note that both the link, and the sender of the e-mail are unrelated to Foyer.lu.
When clicking on the link hXXps://ssowebauth[.]lefoyer[.]lu, a first basic page that asks the victim name and date of birth is presented. Once that information is provided, the web page redirects the victim to a fake credit card form. After which the victim is finally redirected to a fake Luxtrust phishing page, where the ultimate goal is to collect Luxtrust token one-time-passwords and credentials.
Example