INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Revolut Customers Targeted with New Wave of Phishing Attacks
| 2026-10-01 11:30 CRITICAL MEDIUM PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A phishing campaign targeting Free Mobile customers in France appeared after a data breach, with convincing emails that closely copied the company's official website and email templates. The attackers used a link to redirect users to various domains hosted by Cloudflare, which were registered just a month ago, including [IOC HIDDEN • LOGIN REQUIRED]. One employee received such an email on September 30, prompting the company to warn its customers about the scam. To stay safe, Free Mobile advises treating unexpected messages with caution and not following links in unsolicited emails; instead, users can open the official app or website directly or call the help line at 3244.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
s•••••.ink
bl•••••.to
re•••••.fr
mo•••••.fr
fr•••@kn•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
IT
FR
cryptocurrencycryptocurrency
financefinance
Incident Timeline
October 2024
Threat actors used convincing phishing emails to target Free Mobile customers after the October 2024 data breach.
Click on any entity below to view its context and source!
organisation
Malwarebytes Browser Guard
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically.
organisation
Cloudflare
This final domain,
espace-free-mobile.pro
, is hosted by Cloudflare and was registered just a month ago.
organisation
Free Mobile
Since the breach, we’ve seen many poorly written scam campaigns targeting Free Mobile customers.
organisation
Malwarebytes Scam Guard
Malwarebytes Scam Guard
can help you determine whether an email is a scam and advise you on what to do next.
September 14
Threat actors sent convincing free mobile phishing emails to victims just two days after a bank acknowledged a data breach.
Wednesday, September 30
Threat actors sent convincing phishing emails to a Free Mobile customer after the company's data breach.
Click on any entity below to view its context and source!
tactic
Phishing
One of our employees, who is a Free Mobile customer, received this phishing email on Wednesday, September 30.
2026/10/01
Threat actors impersonated Italian law enforcement to compromise email accounts and send convincing phishing emails targeting Revolut customers.
Click on any entity below to view its context and source!
organisation
CNIL
Free Mobile, one of France’s main cellular providers,
was fined €27 million
by France’s data protection regulator, the CNIL, in January over failures to protect customer data.
financial
€27 providers
Free Mobile, one of France’s main cellular providers,
was fined €27 million
by France’s data protection regulator, the CNIL, in January over failures to protect customer data.
organisation
Revolut Customers Targeted
Revolut Customers Targeted with New Wave of Phishing Attacks.
organisation
Revolut
Hackers have seized on a data breach at digital financial firm Revolut to try and harvest more account information from customers, according to Malwarebytes.
organisation
Revolut Customers Urged
Revolut Customers Urged to Remain Cautious
In the meantime, Malwarebytes encouraged Revolut customers to
Not follow links in unsolicited messages, and go directly to the app if notified about an account issue
Check the domain in the browser address bar to check it’s legitimate
Use an up-to-date, real-time anti-malware solution on device
Details continue to emerge about the breach itself.
organisation
European Investigation Orders
It appears that it targeted the bank’s Lithuanian-regulated entity because it is legally obliged to respond to European Investigation Orders.
organisation
KYC
To send Revolut the fake requests for KYC information, the threat actors impersonated Italian law enforcement by compromising Italian Ministry of the Interior email accounts using infostealer logs.
organisation
Interior
To send Revolut the fake requests for KYC information, the threat actors impersonated Italian law enforcement by compromising Italian Ministry of the Interior email accounts using infostealer logs.
Tactical Metrics
Metrics
financial
27,000,000
Providers
Click for context!
Free Mobile, one of France’s main cellular providers,
was fined €27 million
by France’s data protection regulator, the CNIL, in January over failures to protect customer data.
Intelligence Sources
Infosecurity-Magazine
2026-09-21
Revolut Customers Targeted with New Wave of Phishing Attacks
Infosecurity-Magazine
Malware Bytes
2026-10-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:14
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
CNIL
entity
3x
tactic
Cyber Operation Type
Phishing
tactic
3x
timeline
Temporal Reference
Wednesday, September 30
date
2x
target region
Target Country
France
country
Contextual Telemetry
Context Block
4 METRICS
financial
Providers
27,000,000
providers
general metric
Entities
2
entities
industry
Targeted Sector
Government
sector
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.