Explanation
Threat actors are using a Lufthansa Miles&More phishing theme to collect credit card credentials.
The phishing mail leads the user to believe that the e-mail was sent by Lufthansa Miles & More Credit Card Service
on behalf of the Deutschen Kreditbank AG (DKB).
The pretext to click on the link is that the user’s Miles&More account needs to be upgraded to support strong authentication.
Clicking on “Ihr Konto jetzt einrichten” takes the user to the landing page, asking for account credentials.
Next, a form asking for credit card credentials are shown, followed by a form requesting the smsTAN.
Note that both the the link and the sender of the e-mail are unrelated to Lufthansa Miles & More and DKB.
Example