Free Mobile customers hit by polished invoice phishing

Published

A demand for 9.99 euros, a threat to suspend your phone line, and an email that looks exactly like the real thing. Researchers at Malwarebytes warn that customers of Free Mobile, one of France's main mobile carriers, are receiving a far more convincing phishing campaign than the clumsy scams that have followed the company's data breach.

That breach matters here. Malwarebytes notes that the October 2024 incident gave an unauthorized party access to sensitive customer records, including bank account details and login information, and that France's data protection regulator, the CNIL, fined Free Mobile 27 million euros over it in January. Since then, the company's customers have been a steady target.

A copy good enough to fool a careful reader

One Malwarebytes employee who is a Free Mobile customer received the email on Wednesday, September 30. It used the same logo and template as the carrier's legitimate messages and carried a link that appeared to point to a free.fr regularisation page. The sender, though, was freemobile-regularisation[at]knowledgegrowthcenter[.]help.

Clicking the link runs through a URL shortener to espace-free-mobile[.]pro, a Cloudflare-hosted domain registered about a month ago, and ends on a page that asks for credit card details to settle the supposed unpaid invoice. Malwarebytes says the page looks authentic, which is what sets this run apart from the many poorly written Free Mobile scams it has tracked since the breach.

The same lure has been getting sharper since July

The researchers first saw the same campaign in July using a less convincing redirect chain through a generic hosting subdomain. More recent waves moved to lookalike domains, all behind Cloudflare. Domains Malwarebytes recorded include:

Go to the app or call 3244, never the link

Malwarebytes advises Free Mobile customers not to follow links in unsolicited emails about their account or bills. Open the official Free Mobile app or the carrier's website directly, check that the address bar reads mobile[.]free[.]fr, or call the official help line on 3244. Recent breach reporting across France, including 99 reported breaches at state services, shows how much French personal data is in circulation for scammers to work with.

The lesson outlives this one campaign: a breach does not end when the regulator's fine is paid, because the stolen data keeps making each new lure more believable.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions