Explanation
Threat actors are using a Guichet.lu phishing theme to collect personal information and credit card credentials.
The attack begins with a fake SMS asking to pay a fee.
The SMS text reads as follows:
Veuillez régulariser votre contravention avant sa majoration. Veuillez vous rendre sur: csa-services-public.com
from: +32 7700051066215
Please note the first use of - instead of . in the link and the top-level domain of com instead of lu. The legitimate link is https://csa.services-publics.lu/trpat-fo/jsp/display_home.
When clicking on the link, the victim is taken to the landing page, where they have to enter their license plate number and e-mail address.
Once this information is provided, personal information is requested, after which credit card credentials are asked.
Example