Explanation
Threat actors are using a GLS Luxembourg theme to collect email credentials.
The phishing mail leads the user to believe that the delivery of a parcel was unsuccessful and an update of the address is needed.
By clicking on the link ‘‘Reprogrammer la livraison’’ the user is redirected to a page showing fake parcel information. After this, a page with a
button to update address details is shown (“Mettre à jour des détails de livraison”)
After clicking the button, a form requesting personal information is shown.
Once this information is provided, first a page with a summary of the entered information is shown, after which a form asking for credit card credentials is presented.
Example