Explanation
Threat actors are using a GLS Luxembourg theme to collect email credentials.
The phishing mail leads the user to believe that the delivery of a parcel was unsuccessful and an update of the delivery address is needed.
By clicking on the link ‘Mettre à jour l’adresse de livraison’ the user is first redirected to a start page.
After clicking on ‘Mettre à jour les détails de livraison’, they are redirected to a page showing a fake page to chose the delivery method.
The user is then asked to provide personal information, after which a summary page is shown.
Finally, a form asking for credit card credentials is shown
Example