Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach
Free Mobile phishing emails (unpaid €9.99 invoice lure) (TL-2026-2842) is a medium-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects Free Mobile (Iliad Group) Free Mobile subscribers (brand impersonated, maps to 7 MITRE ATT&CK techniques (T1204.001, T1566.002, T1583.001), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-2842
- Threat ID
- TL-2026-2842
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- telecoms, consumer
- Target regions
- france
- Detection rules
- 9
- Indicators of compromise
- 21
Malwarebytes reports convincing phishing emails impersonating French carrier Free Mobile, claiming an unpaid €9.99 invoice threatens service suspension and redirecting victims through URL-shortener chains to a credit card collection form on Cloudflare-fronted lookalike domains. The campaign follows the October 2024 Free/Free Mobile breach (24 million subscriber contracts, including IBANs) that CNIL fined at €42 million in January 2026.
How Free Mobile phishing emails (unpaid €9.99 invoice lure) works
On 30 September 2026 a Malwarebytes employee received a phishing email, sent from freemobile-regularisation@knowledgegrowthcenter.help, that reproduced Free Mobile's branding and templates and claimed an unpaid invoice of €9.99 would lead to suspension of service. The message's link points to the URL shortener u2l.ai (https://u2l.ai/Q5YwFz301), which redirects (HTTP 302) to https://espace-free-mobile.pro/Ds41LE/ and then to a /regularisation/ page carrying an 'impaye' (unpaid) query parameter. The final page presents a form designed to look authentic and requests the victim's credit card details. Malwarebytes notes the final domain is hosted on Cloudflare and was registered about a month before the September campaign.
The same lure and the same /regularisation/ page layout were seen earlier. A July 2026 variant used https://bly.to/93kie5u redirecting to https://s1181402.ha026.t.mydomain.zone/mbl/ and then /mbl/regularisation/?impaye=. Further variants chain https://s.ink/jmCnZZ to https://freesas.info/Cf4tP/ and https://bly.to/jabwpf6 to https://regularisation-free.info/portail/. Several shorteners (u2l.ai, bly.to, s.ink) and multiple throwaway lookalike domains are rotated across waves.
Context: in October 2024 attackers accessed the IT systems of Free and its subsidiary Free Mobile and obtained data relating to 24 million subscriber contracts, including personal identification details, login information and bank details (IBAN/BIC). A threat actor using the handle 'drussellx' posted 43.6 GB of the data on BreachForums (per CyberInsider). On 13 January 2026 CNIL fined Free Mobile €27 million and Free €15 million (€42 million total), citing insufficiently robust VPN authentication, ineffective detection of abnormal behaviour, deficient breach notifications and excessive retention of former-subscriber data. French reporting (UniversFreebox/Alloforfait) describes a phishing wave that personalises emails with subscriber name, customer number and plan amount, data very likely originating from the 2024 leak. The Malwarebytes article does not itself state that the phishing emails contain breach-derived personal data, and it states no attribution, CVE or CVSS. No link between the breach actor and the phishing operators is established in the sources.
Defender guidance from the sources: verify billing status only through the official Free Mobile app, https://mobile.free.fr, or the 3244 helpline; check the address bar against legitimate domains; Free's legitimate sender addresses include freemobile@free-mobile.fr and freetelecom.fr addresses; French users can report to Signal Spam or cybermalveillance.gouv.fr. Anyone who entered card data should contact their bank to block the card and watch for further fraud.
MITRE ATT&CK techniques used in TL-2026-2842
Execution
Initial Access
Resource Development
T1583.001 Domains; T1583.006 Web Services
Reconnaissance
Impact
Defense Evasion
Affected products and versions in Free Mobile phishing emails (unpaid €9.99 invoice lure)
- Free Mobile (Iliad Group) — Free Mobile subscribers (brand impersonated; customers targeted)
Remediation for Free Mobile phishing emails (unpaid €9.99 invoice lure)
Immediate actions
- Block the sender domain knowledgegrowthcenter.help and the lookalike domains espace-free-mobile.pro, freesas.info and regularisation-free.info at the mail gateway, DNS and web proxy
- Block or inspect redirects through the shorteners u2l.ai, bly.to and s.ink where not business-required
- Customers who entered card details should contact their bank to block the card and monitor statements
- Report phishing to Signal Spam or cybermalveillance.gouv.fr and delete the message
Workarounds
- Use browser anti-phishing protection (e.g. Malwarebytes Browser Guard) to block known phishing pages
Longer-term hardening
- Educate subscribers to check billing only via the Free Mobile app, mobile.free.fr or the 3244 helpline
- Monitor newly registered lookalike domains of the brand (free, free-mobile, regularisation, espace) and request takedown
- Enforce DMARC reject on legitimate sending domains so spoofed mail is easier to filter
Timeline of Free Mobile phishing emails (unpaid €9.99 invoice lure)
- Attackers access IT systems of Free and Free Mobile, obtaining data on 24 million subscriber contracts incl. IBANs; CNIL later cites weak VPN authentication; actor 'drussellx' posts 43.6 GB on BreachForums
- CNIL fines Free Mobile €27 million and Free €15 million (€42 million total) for GDPR Articles 32, 34 and 5(1)(e) violations
- EDPB publishes news item on the €42 million Free Mobile / Free fine
- Earlier phishing variant observed in July 2026 (day approximate; month per Malwarebytes): bly.to/93kie5u redirecting to s1181402.ha026.t.mydomain.zone/mbl/regularisation/
- Approximate registration of the final-hop domain, about one month before the September campaign (per Malwarebytes; exact date not given)
- Malwarebytes employee receives the €9.99 unpaid-invoice phishing email from freemobile-regularisation@knowledgegrowthcenter.help
- Malwarebytes publishes analysis of the Free Mobile phishing campaign with redirect chains and indicators
Sources cited for Free Mobile phishing emails (unpaid €9.99 invoice lure)
- Malwarebytes: Convincing Free Mobile phishing emails appear after data breach
- CNIL: Data breach - FREE MOBILE and FREE fined
- EDPB: Data breach - FREE MOBILE and FREE fined €42 million
- CyberInsider: France fines Free €42 million over 2024 data breach affecting 24M clients
- The Record: France data regulator fine
- UniversFreebox: Une nouvelle vague de phishing cible les abonnés Free Mobile avec leurs propres identifiants
- Alloforfait: Free Mobile - une nouvelle vague de phishing vise les abonnés dont les données ont fuité en 2024
More in phishing
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breach
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
Detection coverage for TL-2026-2842
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2842 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.