← Security Awareness Hub Monthly series

Scam of the Month

Once a month, one real scam taken apart — anonymised, redacted, defanged. The lure, why it works, the kill-chain, and the moments you could have bailed out.

Most awareness content is generic and evergreen. This series is local and current: pulled from what's actually circulating in Luxembourg and the Greater Region. Names, account numbers and URLs are scrubbed so you can study the pattern without exposing victims — or the brands they impersonate.

Why this series
  • Local + current beats generic-and-evergreen for trust and shareability.
  • A real artefact — a redacted SMS, a fake CSSF email — is more credible than abstract advice.
  • The "where you could have bailed" framing teaches a transferable instinct, not a single fact.
  • Repeatable format, monthly cadence — come back the first of the month.

Editorial rules

  • Never name the impersonated brand as if accusing them — they're a victim of impersonation too.
  • Every malicious URL is defanged (e.g. hxxps://) so you cannot accidentally type it live.
  • No victim-blaming. The whole point is "this is designed to fool smart people."
  • Each issue stays tight — the artefact does the heavy lifting.

Issues

🇱🇺 Spot one in the wild?

  • Forward the message to SPAMBEE (spambee.lu).
  • Report a phishing URL to CIRCL via URL-Abuse.
  • If money moved or you tapped approve: I've Been Hit.
Building this series openly. If you've received something Luxembourg-relevant — an unusual SMS, a fake regulator email, a quishing sticker — anonymised tips are welcome via johlem.net.