Scam of the Month
Once a month, one real scam taken apart — anonymised, redacted, defanged. The lure, why it works, the kill-chain, and the moments you could have bailed out.
Most awareness content is generic and evergreen. This series is local and current: pulled from what's actually circulating in Luxembourg and the Greater Region. Names, account numbers and URLs are scrubbed so you can study the pattern without exposing victims — or the brands they impersonate.
Why this series
- Local + current beats generic-and-evergreen for trust and shareability.
- A real artefact — a redacted SMS, a fake CSSF email — is more credible than abstract advice.
- The "where you could have bailed" framing teaches a transferable instinct, not a single fact.
- Repeatable format, monthly cadence — come back the first of the month.
Editorial rules
- Never name the impersonated brand as if accusing them — they're a victim of impersonation too.
- Every malicious URL is defanged (e.g.
hxxps://) so you cannot accidentally type it live. - No victim-blaming. The whole point is "this is designed to fool smart people."
- Each issue stays tight — the artefact does the heavy lifting.
Issues
🇱🇺 Spot one in the wild?
- Forward the message to SPAMBEE (spambee.lu).
- Report a phishing URL to CIRCL via URL-Abuse.
- If money moved or you tapped approve: I've Been Hit.
Building this series openly. If you've received something Luxembourg-relevant — an unusual SMS, a fake regulator email, a quishing sticker — anonymised tips are welcome via johlem.net.