VYPR
breachPublished Oct 1, 2026· Updated Oct 2, 2026· 1 source

Sophisticated Phishing Campaign Targets Free Mobile Customers Post-Data Breach

A new, highly convincing phishing campaign is targeting Free Mobile customers with emails that mimic official communications, days after a significant data breach exposed sensitive customer information.

Following a substantial data breach that impacted Free Mobile customers and resulted in a €27 million fine for the French cellular provider, a sophisticated phishing campaign has emerged, posing a significant threat to users. The breach, which occurred in October 2024, exposed sensitive customer records, including bank account details and login credentials, creating fertile ground for malicious actors.

While numerous poorly crafted scam attempts have surfaced since the breach, a recent campaign stands out due to its high degree of polish and mimicry. This new wave of phishing emails closely replicates the design and templates of legitimate Free Mobile communications, making them difficult to distinguish from authentic messages. One employee received such an email, which, despite originating from a suspicious domain (freemobile-regularisation[@]knowledgegrowthcenter[.]help), used the official Free Mobile logo and template.

The phishing emails inform recipients that an outstanding invoice of €9.99 requires payment to prevent service suspension. Crucially, the included links, which initially appear to lead to legitimate Free Mobile domains like regularisation.free.fr, initiate a multi-stage redirection chain. This chain is designed to obscure the true destination and bypass initial security filters.

These redirection chains ultimately lead to domains hosted by Cloudflare, such as espace-free-mobile.pro, which was registered only a month prior to the observed campaign. The final landing pages are convincingly designed, presenting users with a form that requests sensitive credit card details. This level of authenticity marks a significant escalation from earlier, less sophisticated phishing attempts seen in July, which utilized less convincing redirection chains and domains.

Researchers have observed a progression in the campaign's tactics, with more recent iterations employing domains like freesas.info and regularisation-free.info, all leveraging Cloudflare for hosting. This reliance on Cloudflare, while common for legitimate services, also provides a degree of anonymity and infrastructure for malicious actors to operate.

The campaign's sophistication lies in its ability to leverage the trust associated with a major service provider like Free Mobile, coupled with the exploitation of a recent, high-profile data breach. By using convincing email templates, seemingly legitimate-looking (though ultimately malicious) domains, and a multi-stage redirection process, attackers aim to maximize their success rate in harvesting financial information.

To combat such threats, users are advised to exercise extreme caution with unsolicited emails, especially those demanding payment or threatening service disruption. Instead of clicking on links within suspicious emails, individuals should directly access the official Free Mobile app or website, or contact customer support through verified channels. Verifying the URL in the browser's address bar is also critical to ensure it matches the legitimate domain.

Security solutions like Malwarebytes Browser Guard can actively detect and block these phishing pages, while up-to-date anti-malware software with web protection components provides a crucial layer of defense. Tools like Malwarebytes Scam Guard can further assist users in identifying and navigating potential scams.

Synthesized by Vypr AI