Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Convincing Phishing Emails Target Free Mobile Customers After 2024 Data Breach

After a 2024 breach of Free Mobile customer records, attackers launched sophisticated phishing emails that replicate the carrier’s branding and request payment details. The episode underscores the need for robust security‑awareness training and email‑authentication controls to maintain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
malwarebytes.com

Convincing Phishing Emails Target Free Mobile Customers After 2024 Data Breach

What Happened – After a 2024 breach that exposed bank and login details of Free Mobile customers, threat actors began sending highly‑crafted phishing emails that mimic the carrier’s branding and template. The messages use newly‑registered domains (e.g., espace‑free‑mobile.pro) and multi‑step redirection chains to harvest credit‑card data.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous security‑awareness training and simulated phishing exercises to detect and deter credential‑theft attempts.
  • Highlights the importance of email‑authentication controls (DMARC, SPF, DKIM) and monitoring of brand‑related domains as part of a defensible audit trail.
  • Aligns with the control objective of “Identity and Access Management – User Awareness and Training,” which satisfies multiple frameworks (e.g., NIST CSF 2.0) with a single evidence set.

Who Is Affected – Telecom operators, mobile carriers, and any organization that stores customer payment or login data.

Recommended Actions

  • Conduct an immediate phishing‑simulation campaign for all staff and customers.
  • Verify and enforce DMARC, SPF, and DKIM for all outbound domains; monitor for look‑alike registrations.
  • Document training completion and email‑auth policy as evidence for audit readiness. Source: Malwarebytes Labs

Technical Notes – The phishing flow uses short‑link services (u2l.ai, s.ink) that resolve to Cloudflare‑hosted domains registered within the last month. The final landing page collects credit‑card numbers via a form that mirrors Free Mobile’s invoice portal. Source: same as above

📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/10/free-mobile-phishing-texts-appear-days-after-data-breach ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →