Convincing Free Mobile phishing emails appear after data breach
Cybersecurity Classified by Officially
Free Mobile, one of France’s main cellular providers, was fined €27 million by France’s data protection regulator, the CNIL, in January over failures to protect customer data. The October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information. Since the breach, we’ve seen many poorly written scam campaigns targeting Free Mobile customers.
However, over the past few weeks, a well-written scam has appeared, closely copying the design of the official Free Mobile website and email templates.
One of our employees, who is a Free Mobile customer, received this phishing email on Wednesday, September 30. The message used the same logo and template as legitimate emails from the company, but came from the suspicious email address freemobile-regularisation[@]knowledgegrowthcenter[.]help. It included a link that appeared to point to regularisation.free.fr :
The email tells the user that an invoice of €9.99 needs to be paid to avoid having the customer’s service suspended. Clicking the link opens a redirection chain:
1. https://u2l.ai/Q5YwFz301
2. https://espace-free-mobile.pro/Ds41LE/302
3. https://espace-free-mobile.pro/Ds41LE/regularisation/?impaye=92a9e77d…200This final domain, espace-free-mobile.pro, is hosted by Cloudflare and was registered just a month ago.
The final link opens a convincing page with a form asking for credit card details:
The phishing page looks authentic, which sets this campaign apart from many of the Free Mobile scams we’ve seen since the breach.
We initially saw the same campaign using less convincing redirection chains, like this example from July:
1. https://bly.to/93kie5u
2. https://s1181402.ha026.t.mydomain.zone/mbl/
3. https://s1181402.ha026.t.mydomain.zone/mbl/regularisation/?impaye=505…More recently, we’ve seen more authentic-looking domains, all hosted by Cloudflare:
This is an extract. The publication continues at the source.
Read the original at the source: https://www.malwarebytes.com/blog/threat-intel/2026/10/revolut-phishing-texts-appear-days-after-data-breach-clone
Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Malwarebytes — imported from official source
- Official source
- https://www.malwarebytes.com/blog/feed/index.xml RSS
- Imported
- October 02, 2026 14:00
- Versions
- 1 recorded
- Identity
https://www.malwarebytes.com/blog/threat-intel/2026/10/revolut-phishing-texts-appear-da...