Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach

Free Mobile phishing emails (unpaid €9.99 invoice lure) (TL-2026-2842) is a medium-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects Free Mobile (Iliad Group) Free Mobile subscribers (brand impersonated, maps to 7 MITRE ATT&CK techniques (T1204.001, T1566.002, T1583.001), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-2842

Threat ID
TL-2026-2842
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-10-01
Last reviewed
2026-10-01
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
telecoms, consumer
Target regions
france
Detection rules
9
Indicators of compromise
21

Malwarebytes reports convincing phishing emails impersonating French carrier Free Mobile, claiming an unpaid €9.99 invoice threatens service suspension and redirecting victims through URL-shortener chains to a credit card collection form on Cloudflare-fronted lookalike domains. The campaign follows the October 2024 Free/Free Mobile breach (24 million subscriber contracts, including IBANs) that CNIL fined at €42 million in January 2026.

How Free Mobile phishing emails (unpaid €9.99 invoice lure) works

On 30 September 2026 a Malwarebytes employee received a phishing email, sent from freemobile-regularisation@knowledgegrowthcenter.help, that reproduced Free Mobile's branding and templates and claimed an unpaid invoice of €9.99 would lead to suspension of service. The message's link points to the URL shortener u2l.ai (https://u2l.ai/Q5YwFz301), which redirects (HTTP 302) to https://espace-free-mobile.pro/Ds41LE/ and then to a /regularisation/ page carrying an 'impaye' (unpaid) query parameter. The final page presents a form designed to look authentic and requests the victim's credit card details. Malwarebytes notes the final domain is hosted on Cloudflare and was registered about a month before the September campaign.

The same lure and the same /regularisation/ page layout were seen earlier. A July 2026 variant used https://bly.to/93kie5u redirecting to https://s1181402.ha026.t.mydomain.zone/mbl/ and then /mbl/regularisation/?impaye=. Further variants chain https://s.ink/jmCnZZ to https://freesas.info/Cf4tP/ and https://bly.to/jabwpf6 to https://regularisation-free.info/portail/. Several shorteners (u2l.ai, bly.to, s.ink) and multiple throwaway lookalike domains are rotated across waves.

Context: in October 2024 attackers accessed the IT systems of Free and its subsidiary Free Mobile and obtained data relating to 24 million subscriber contracts, including personal identification details, login information and bank details (IBAN/BIC). A threat actor using the handle 'drussellx' posted 43.6 GB of the data on BreachForums (per CyberInsider). On 13 January 2026 CNIL fined Free Mobile €27 million and Free €15 million (€42 million total), citing insufficiently robust VPN authentication, ineffective detection of abnormal behaviour, deficient breach notifications and excessive retention of former-subscriber data. French reporting (UniversFreebox/Alloforfait) describes a phishing wave that personalises emails with subscriber name, customer number and plan amount, data very likely originating from the 2024 leak. The Malwarebytes article does not itself state that the phishing emails contain breach-derived personal data, and it states no attribution, CVE or CVSS. No link between the breach actor and the phishing operators is established in the sources.

Defender guidance from the sources: verify billing status only through the official Free Mobile app, https://mobile.free.fr, or the 3244 helpline; check the address bar against legitimate domains; Free's legitimate sender addresses include freemobile@free-mobile.fr and freetelecom.fr addresses; French users can report to Signal Spam or cybermalveillance.gouv.fr. Anyone who entered card data should contact their bank to block the card and watch for further fraud.

MITRE ATT&CK techniques used in TL-2026-2842

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.006 Web Services

Reconnaissance

T1598.003 Spearphishing Link

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Free Mobile phishing emails (unpaid €9.99 invoice lure)

  • Free Mobile (Iliad Group) — Free Mobile subscribers (brand impersonated; customers targeted)

Remediation for Free Mobile phishing emails (unpaid €9.99 invoice lure)

Immediate actions

  • Block the sender domain knowledgegrowthcenter.help and the lookalike domains espace-free-mobile.pro, freesas.info and regularisation-free.info at the mail gateway, DNS and web proxy
  • Block or inspect redirects through the shorteners u2l.ai, bly.to and s.ink where not business-required
  • Customers who entered card details should contact their bank to block the card and monitor statements
  • Report phishing to Signal Spam or cybermalveillance.gouv.fr and delete the message

Workarounds

  • Use browser anti-phishing protection (e.g. Malwarebytes Browser Guard) to block known phishing pages

Longer-term hardening

  • Educate subscribers to check billing only via the Free Mobile app, mobile.free.fr or the 3244 helpline
  • Monitor newly registered lookalike domains of the brand (free, free-mobile, regularisation, espace) and request takedown
  • Enforce DMARC reject on legitimate sending domains so spoofed mail is easier to filter

Timeline of Free Mobile phishing emails (unpaid €9.99 invoice lure)

  • Attackers access IT systems of Free and Free Mobile, obtaining data on 24 million subscriber contracts incl. IBANs; CNIL later cites weak VPN authentication; actor 'drussellx' posts 43.6 GB on BreachForums
  • CNIL fines Free Mobile €27 million and Free €15 million (€42 million total) for GDPR Articles 32, 34 and 5(1)(e) violations
  • EDPB publishes news item on the €42 million Free Mobile / Free fine
  • Earlier phishing variant observed in July 2026 (day approximate; month per Malwarebytes): bly.to/93kie5u redirecting to s1181402.ha026.t.mydomain.zone/mbl/regularisation/
  • Approximate registration of the final-hop domain, about one month before the September campaign (per Malwarebytes; exact date not given)
  • Malwarebytes employee receives the €9.99 unpaid-invoice phishing email from freemobile-regularisation@knowledgegrowthcenter.help
  • Malwarebytes publishes analysis of the Free Mobile phishing campaign with redirect chains and indicators

Sources cited for Free Mobile phishing emails (unpaid €9.99 invoice lure)

More in phishing

Detection coverage for TL-2026-2842

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2842 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats