Skip to content

Image: malwarebytes.com · rights & removal

Executive Summary

A mobile provider, Free Mobile, was fined €27 million by the CNIL for failures in protecting customer data following a breach in October 2024 that exposed sensitive records like bank details and login information. Following this breach, there have been numerous scam campaigns targeting customers. A recent phishing email was distributed to a customer on September 30, mimicking legitimate Free Mobile branding using official logos and email templates. This email directed the recipient to a suspicious address (`freemobile-regularisation[@]knowledgegrowthcenter[.]help`) and provided a link suggesting a €9.99 invoice payment to prevent service suspension. The link initiated a redirection chain involving domains like `u2l.ai`, `espace-free-mobile.pro`, and other domains hosted by Cloudflare, culminating in a page requesting credit card details. This phishing attempt differs from previous scams by using more authentic-looking domains.

Facts Only

* Free Mobile was fined €27 million by the CNIL over data protection failures.
* An October 2024 breach allowed unauthorized access to customer records, including bank account details and login information.
* A phishing email was received by a customer on Wednesday, September 30.
* The email used the official Free Mobile logo and template but originated from `freemobile-regularisation[@]knowledgegrowthcenter[.]help`.
* The email contained a link pointing to `regularisation.free.fr`.
* The link initiated a three-step redirection: to `https://u2l.ai/Q5YwFz301` then `https://espace-free-mobile.pro/Ds41LE/302` and finally to `https://espace-free-mobile.pro/Ds41LE/regularisation/?impaye=92a9e77d…200`
* The final destination domain, `espace-free-mobile.pro`, was hosted by Cloudflare and registered within one month of the incident.
* Other observed phishing links included domains such as `s.ink/jmCnZZ` and `freesas.info`.
* Malwarebytes Browser Guard detected and blocked a scam directly in the browser.

Full Take

The narrative demonstrates a concerning evolution in phishing tactics, shifting from less convincing redirection chains to employing domains hosted by major infrastructure providers like Cloudflare, suggesting a growing sophistication in impersonation. The pattern reveals a mechanism where legitimate branding is weaponized to bypass initial skepticism, exploiting existing trust in the brand identity. The structure of the attack—using an urgent financial threat (suspension) tied to official-looking correspondence—leverages fear and immediacy to force action. The presence of multiple, seemingly novel domains linked through complex redirection chains points to a strategy of obfuscation, making forensic tracing difficult for the average user while maximizing the impact of the initial lure. This process echoes historical social engineering where institutional authority is leveraged against personal security. The implication for agency lies in how easily trust can be substituted with synthetic authenticity; the defense shifts from verifying the sender’s identity to rigorously inspecting the underlying infrastructure, suggesting that cognitive sovereignty requires adopting a default stance of high skepticism toward unsolicited digital demands, regardless of visual fidelity.
Bridge Questions: How can institutions establish an immediate, verifiable verification protocol for critical account notifications that supersedes reliance on visual branding? What structural changes are necessary in digital ecosystems to make tracing ephemeral domain registrations less trivial for malicious actors? When trust is engineered through mimicry, what is the practical cognitive framework required to allocate security resources effectively under conditions of perceived authenticity?

From the original · Malwarebytes Labs

Free Mobile, one of France’s main cellular providers, was fined €27 million by France’s data protection regulator, the CNIL, in January over failures to protect customer data. The October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information.
Read the full story at malwarebytes.com

Sentinel — Likely Human

Confidence

The text reads like a report detailing a data breach followed by a specific case study of evolving phishing attacks, exhibiting strong evidence of human investigation and observation rather than purely generative synthesis.

Signals Detected
low severity: Inconsistent flow between factual reporting and highly narrative descriptions of observed phishing attempts.
low severity: Strong flow regarding the sequence of events (breach -> scam evolution), but the shift to prescriptive advice feels inserted.
medium severity: The detailed enumeration of specific, evolving URLs and links suggests granular, likely manually collected or observed data, typical of investigative reporting, rather than synthesized noise.
low severity: The inclusion of explicit security product promotion (Malwarebytes) as the concluding action seems contextually driven by the source's interest rather than purely journalistic objective presentation.
Human Indicators
Specific, evolving tracking of domain patterns and URL structures suggests direct observation or forensic collection.
The structure shifts from reporting a legal fine to demonstrating specific, current threats, which reflects an investigative narrative arc.
Convincing Free Mobile phishing emails appear after data breach | Huntaegis