Explanation
Threat actors are targeting Société Générale customers to collect account information.
The phishing mail leads the user to believe that their bank account has recently received a transfer.
By opening the attachment and clicking on the link the user is redirected to the phishing landing page. This page asks for account number and password
Afterwards, the user has to enter an SMS code.
Once this information is provided, the user then has to provide his ID card number, after which another SMS code is asked.
Example