INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Free Mobile Phishing Emails Spotted After Data Breach Incident
| 2026-10-03 06:51 DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
Following the October 2024 data breach at French telecommunications provider Free Mobile, threat actors have increased phishing activity targeting the company's customers. The breach exposed sensitive information, including bank account details and login credentials, and was followed by numerous scam campaigns. Earlier campaigns were reportedly poorly written, but a more recent operation uses professionally designed emails and websites that closely imitate Free Mobile's branding, templates, and account-related communications. This sophisticated phishing campaign is targeting the finance sector in France, specifically telecommunications companies, with an emphasis on data breach tactics. The attackers are utilizing France as their target region, Finance as their targeted industry, Phishing as their cyber operation type, and Telecommunications as their targeted sector. Furthermore, this malicious activity occurred in October 2024, resulting from the identified entity Free Mobile's data breach.
Technical Mitigations AI-generated
• Implement browser guard to detect and block malicious websites.
• Utilize Cloudflare's security features, such as DNS over HTTPS (DoH) or DNS over TLS (DoT), to protect against phishing attacks.
• Leverage email filtering solutions that can identify and flag suspicious emails based on their content, sender reputation, and other factors.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fr•••@kn•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
es•••••.pro
fr•••••.info
u2•••••.ai
re•••••.info
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Intelligence Sources
AlienVault OTX
2026-10-03