Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 05, 2026 · 9 min read

Free Mobile Phishing Emails Now Copy the Real Templates

On September 30, 2026, a Free Mobile customer at Malwarebytes received a fake €9.99 invoice that matched the carrier's own email design and led to a card harvesting page. There is no new breach behind it. The bait comes from the October 2024 theft of 24 million subscriber contracts, and it keeps getting better.

For two years, scams aimed at Free Mobile customers were easy to laugh off. Broken French, odd logos, sender addresses nobody would trust. That has changed. In a October 1, 2026 report, Malwarebytes principal security engineer Jérôme Boursier described a new scam "closely copying the design of the official Free Mobile website and email templates." The sample message arrived in the inbox of a Malwarebytes employee who is a Free Mobile customer.

Some coverage frames this as phishing that follows a fresh data breach. We could not find one. Free has posted no new breach notice, and the Malwarebytes post itself ties the scams to the October 2024 intrusion that France's data regulator fined in January. What is new is the quality of the lure, and the infrastructure behind it.

Key Takeaways

  • Malwarebytes documented a Free Mobile phishing email, received on September 30, 2026, that reused the carrier's logo and template and demanded a €9.99 payment to avoid service suspension.
  • The email came from freemobile-regularisation[@]knowledgegrowthcenter[.]help, a domain registered through Porkbun on September 12, 2026, according to its public RDAP record.
  • Free has announced no new breach as of October 5, 2026; the scams trace back to the October 2024 attack on 24 million subscriber contracts, for which the CNIL fined Free Mobile €27 million and Free €15 million.
  • Free says Free Mobile emails come only from freemobile@free-mobile.fr and that its emails and texts never show your bank name, IBAN or BIC in plain text.
A smartphone propped on a marble Paris cafe table beside a croissant and a cup of coffee, its screen showing a blurred carrier style message with an orange button, with a cafe terrace and Haussmann buildings behind

Did Free Mobile Suffer a New Data Breach in 2026?

No new Free Mobile breach has been confirmed as of October 5, 2026; the current phishing wave exploits data stolen in October 2024. We checked Free's help center, the CNIL and French tech press and found no new incident notice. The Malwarebytes post states the history plainly: "The October 2024 breach allowed an unauthorized party to access sensitive customer records."

The scale of that 2024 theft explains why scammers still mine it. The CNIL's sanction notice says the attacker reached personal data covering 24 million subscriber contracts, including IBANs of people who were customers of both Free Mobile and Free. On January 13, 2026, the regulator fined Free Mobile €27 million and Free €15 million, €42 million in total. In a statement carried by Univers Freebox, Free called it a decision of "sévérité inédite" (unprecedented severity) and said it would appeal to the Conseil d'État.

We covered the fine itself in France Fines Free Mobile €42 Million After Hackers Stole 24 Million Customer Records. This piece is about what that stolen data is doing now.

What Does the Fake Free Mobile Email Look Like?

The fake email looks like a routine Free Mobile billing notice: the real logo, the real layout, and a claim that a €9.99 invoice must be paid or the line will be suspended. According to Malwarebytes, the link in the message "appeared to point to regularisation.free.fr," a plausible Free subdomain. It did not go there. Clicking started a redirect chain:

  1. A short link on u2l.ai
  2. A hop to espace-free-mobile.pro
  3. A final page at espace-free-mobile.pro/.../regularisation/?impaye=..., where "impayé" is French for "unpaid"

That last page is "a convincing page with a form asking for credit card details," Malwarebytes wrote, adding that the domain is hosted by Cloudflare. The same operation has rotated through other setups. A July version started on a bly.to short link and ended on a generic hosting subdomain. Later runs used freesas.info and regularisation-free.info, both reached through short links.

Short links do real work for the attacker. They hide the final domain from anyone who hovers, and they let the operator swap the landing page without resending a single email.

Who Registered the Phishing Domains?

All four domains named in the Malwarebytes report were registered through the same registrar, Porkbun LLC, between May and September 2026. We pulled their public registration records through RDAP, the IETF successor to WHOIS, on October 5, 2026. A made up control domain returned a 404, so the lookups were answering for real records:

Domain Role in the campaign Registered
regularisation-free.info Landing page, another run May 3, 2026
freesas.info Landing page, another run May 8, 2026
espace-free-mobile.pro Landing page, September 30 email August 25, 2026
knowledgegrowthcenter.help Sender domain, September 30 email September 12, 2026

A shared registrar does not prove a single operator. The timing tells you more. The sender domain was 18 days old when the email landed, and the landing domain was 36 days old.

The DNS records explain why the scammers bothered with a throwaway domain at all. Free publishes a DMARC policy of p=reject with strict alignment for free-mobile.fr, which tells Gmail and other providers to refuse mail that falsely claims that domain. So the attackers sent from a domain they control, which publishes its own SPF and DMARC records. Authentication checks on a message like that can only confirm it came from knowledgegrowthcenter.help. They say nothing about Free.

How Can You Tell a Real Free Mobile Email From a Fake?

Check the full sender address against the list Free publishes, and never pay or log in from a link in the email. Free's own phishing guidance page gives you most of what you need:

  • Sender: Free says emails to Free Mobile subscribers are sent from freemobile@free-mobile.fr. Freebox customers get mail from info@freetelecom.fr, info-free@freetelecom.fr and info-abonne@freetelecom.fr. A sender name that says "Free Mobile" on top of any other address is fake.
  • Bank details: Free says your bank name, IBAN and BIC "n'apparaissent jamais en clair" (never appear in plain text) in its emails and texts. An email that quotes your IBAN back to you is a scam, however official it looks.
  • Credentials: Free lists a request for your Espace Abonné login and password as a sign of phishing, and tells customers never to share bank details, passwords or one time security codes with anyone.
  • Links: On a computer, hover before you click. A short link, or any domain other than mobile.free.fr, means stop.
  • Texts: Free says its SMS messages are never sent from a number starting with 06 or 07.

The most reliable check skips the email entirely. Free says the latest emails and texts it sent you are stored in your account at mobile.free.fr/account, under Nos communications, then Communications de Free. If the €9.99 notice is not there, Free did not send it. You can also call 3244, Free's support line, which is free from a Free line. If someone calls you claiming to be 3244, Free's advice is to hang up and dial the number yourself.

In Gmail on the web, open the message, click More next to Reply, then Show original. Google's header guide walks through it. The From line in the full header shows the real sending domain, whatever the display name claims.

What This Means for Your Inbox

Breach data stays useful to criminals for years. Tracking the Free campaigns on the public record shows the lures improving step by step:

  • November 2025: Free posted an alert on its help site about an email that "reprend notre identité visuelle et ne contient aucune faute" (copies our visual identity and contains no mistakes), displayed the subscriber's IBAN, and cited a supposed new European regulation. Neozone covered the alert on November 3, 2025.
  • January 2026: Univers Freebox reported emails carrying the subscriber's full name, customer number and plan price, sent from help@assistance.free.fr, an address missing from Free's official sender list.
  • September 2026: the template clone Malwarebytes caught, backed by fresh domains and a redirect chain.

Each wave fixed the flaw that gave the last one away. The usual advice to look for spelling mistakes failed back in 2025. What still works is checking the sender domain and refusing to act on links, and those checks hold up even when the email quotes your real customer number.

This is not only a Free problem. Any company that loses customer names, emails and billing details hands scammers the same raw material. French bank account data has leaked before, as in the FICOBA breach that exposed 1.2 million accounts, and fake billing notices are a standard lure everywhere, as the recent fake ChatGPT billing email shows. If a company that bills you has been breached, expect its brand in your inbox for years.

What Should You Do If You Already Entered Your Card?

Call your bank right away to block the card, then change any password you may have typed into the fake page. That matches Free's own instructions, which also tell you to change the password anywhere else you reused it.

  • Report the email to Signal Spam and cybermalveillance.gouv.fr, the two channels Free names. In Gmail, use More, then Report phishing.
  • Watch your phone for signs of a SIM swap. Free says that if your phone suddenly shows no SIM, no service or emergency calls only, you should go to a Free store or call 3244, alert your bank and change your passwords.
  • Our advice, not Free's: keep checking your bank statements for charges you do not recognize in the weeks that follow.

What Should Companies Take From This?

A breach notice is only the start of a company's job, because the phishing that follows lands on its customers. The CNIL found that Free's first breach emails did not contain all the information GDPR Article 34 requires, leaving people unable to understand the consequences or how to protect themselves.

Free's current help page gets several things right. It publishes an exact list of sender addresses, keeps an archive of real messages inside the customer account, and makes a simple rule public: no IBAN in plain text, ever. A p=reject DMARC policy on free-mobile.fr closes off direct spoofing. Those steps cannot stop a lookalike domain, but they give every customer a test the scammers cannot pass. Any company holding billing data should have the same in place before it needs it.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.