Free Mobile phishing emails mimic official pages after breach

Well-crafted phishing emails that imitate Free Mobile are circulating after a past data breach. Malwarebytes found Cloudflare-hosted domains and redirect chains leading to payment forms asking for card details.

stack of fake invoices, a credit card, padlock, and magnifying glass on a table

Malwarebytes reports a new, convincing phishing campaign targeting Free Mobile customers. According to Malwarebytes, the campaign closely copies Free Mobile email and site templates and sends messages that say an invoice must be paid to avoid service suspension. The phishing pages collect credit card details and are hosted on recently registered domains, many sitting behind Cloudflare.

Free Mobile phishing: how the scam works

Malwarebytes traces the attack back to the fallout from a past breach and regulatory action. The report says Free Mobile was fined €27 million by France's data protection regulator, the CNIL, in January, after an October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information.

Since then, many low-quality scams tried to exploit the breach. The current campaign stands out because the messages and landing pages are well designed and closely match legitimate Free Mobile communications. Malwarebytes describes one example received on Wednesday, September 30, that used Free Mobile's logo and template but originated from the suspicious email address freemobile-regularisation[@]knowledgegrowthcenter[.]help and included a link that appeared to point to regularisation.free.fr.

Malwarebytes documented the redirection chain in that example, which begins with a short tracking URL and ends on a Cloudflare-hosted domain. The company logged this chain:

  1. https://u2l.ai/Q5YwFz301
  2. https://espace-free-mobile.pro/Ds41LE/302
  3. https://espace-free-mobile.pro/Ds41LE/regularisation/?impaye=92a9e77d…200

The final domain, espace-free-mobile.pro, was registered recently and hosts a realistic-looking payment form that asks for credit card information. Malwarebytes also reported earlier and alternate examples that use different short links and domains but the same tactic, for example chains that end on freesas.info and regularisation-free.info, all hosted through Cloudflare.

Why this matters to customers and small organizations

Phishing that closely mimics a trusted service is harder to spot, especially for people who already have an account with that service. Because the Free Mobile breach exposed bank and login data, attackers may have enough context to craft targeted messages that seem legitimate.

Small businesses, nonprofits, and local government teams should pay attention because attackers often reuse tactics and templates across targets. If your organization communicates billing or account notices by email, a convincing fake can confuse staff or customers and lead to financial loss or stolen credentials.

How attackers set up the pages

Malwarebytes notes the campaign uses short redirect links and newly registered domains that imitate the real brand. Hosting through services like Cloudflare is part of the chain, and the final pages include forms that request payment information. The use of familiar logos and templates is what makes this campaign more convincing than earlier, poorly written scams observed after the breach.

Practical steps to protect yourself and your organization

Follow these practical steps, many recommended in the Malwarebytes report:

  • Do not click links in unsolicited emails. If an invoice or account notice looks authentic, go to the official Free Mobile app or type the known official address into your browser directly.
  • Check the address bar in your browser to confirm the domain matches the legitimate site you expect, for example https://mobile.free.fr in this case.
  • When in doubt, contact the company by its official phone line or support channels rather than replying to the email.
  • Use an up-to-date, real-time anti-malware product with web protection on all devices, and enable browser-based protections where available. Malwarebytes notes its Browser Guard and Scam Guard can detect and block these pages.
  • Train staff and volunteers to treat unexpected invoice requests as suspicious and to verify payment requests through a second channel, such as a phone call to a known number.
  • Review who can approve payments in your organization and require a second person to confirm unusual or out-of-cycle charges.

If you want to know what attackers can already learn about your site, check our scan page here: /security.html.

What to watch for going forward

Expect attackers to keep refining their pages and redirect techniques after breaches. Malwarebytes found that the campaign evolved from poorly written redirects to more authentic domains and shorter chains, which increases the chance that people will trust the message and enter payment details. Keep software and protections current, and keep staff alert to the signs of a copied template or spoofed domain.

For more detail on the specific examples and redirect chains Malwarebytes observed, read the full Malwarebytes report.

Sources

This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.

Found this useful? Pass it on to someone who would want to know.

All Scam Alerts posts →

Cookie Notice

We use cookies to enhance your browsing experience and analyze site traffic. By clicking "Accept All", you consent to our use of cookies.