Free Mobile Users Hit by Fake €9.99 Invoice Scam

Malwarebytes · Medium sophistication
Last updated October 2, 2026

After a Free Mobile customer data breach, scammers sent convincing emails that mimic Free Mobile’s real branding and templates. The emails claim a €9.99 unpaid invoice and threaten service suspension, pushing victims to a fake payment page that collects credit card details via redirect links.

Key findings

  • A convincing phishing email copied Free Mobile’s official website/email design and templates.
  • The lure claims an unpaid €9.99 invoice and threatens service suspension.
  • Emails used a suspicious sender domain and hid malicious destinations behind a redirect chain.
  • The final landing page asked for credit card details.
  • Multiple similar campaigns were observed using different redirectors and lookalike domains, often hosted by Cloudflare and recently registered.

Who’s being targeted

  • Commonly targeted roles: All employees (consumer-style phishing awareness), Finance (payment detail vigilance), Customer Support/Helpdesk (handling user reports of phishing).
  • Affected industries: Telecommunications, Consumer/Mobile Services.
  • Attack channels: email, website.
  • Impersonated: Free Mobile billing/support.

Awareness takeaways

  • Don’t click payment/account links in unexpected emails, go to the provider’s app/site directly or call the official number.
  • Verify the real destination domain in the browser address bar before entering payment details.
  • Be suspicious of brand-perfect emails, attackers can copy logos and templates, so branding alone isn’t proof.
  • Train users to watch for redirect chains and lookalike domains that differ from the real company domain.

Red flags to watch for

  • Sender domain doesn’t match Free Mobile (came from a suspicious address)
  • Link text appears to be a Free domain, but redirects to a different domain
  • Pressure/urgency: threat of service suspension over a small payment
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from “Free Mobile”: pay a €9.99 invoice now or your service is suspended. It even uses Free’s real logo and template. But look at the sender: freemobile-regularisation@knowledgegrowthcenter.help. That is not Free Mobile. Click their link and you’re bounced through redirects to a lookalike site hosted behind Cloudflare, ending on a fake Free page asking for your credit card. If you get a surprise €9.99 invoice email, don’t click the link, open the Free Mobile app or go to mobile.free.fr or call 3244 and check your account there.

Similar attacks

Fake Verification Pages Push PavinLoader Malware

Fake Verification Pages Push PavinLoader Malware

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools…

August 24, 2026
ClickLock Stealer Freezes Macs for Passwords

ClickLock Stealer Freezes Macs for Passwords

Researchers found a new macOS infostealer, “ClickLock Stealer,” that uses ClickFix-style fake verification pages to trick people into running Terminal commands. After infection, it shows a realistic macOS password prompt and can effectively lock the Mac until the victim enters the correct password,…

July 21, 2026
TA419 Phishes AI Policy Experts With Microsoft AitM

TA419 Phishes AI Policy Experts With Microsoft AitM

China-aligned threat actor TA419 ran real credential-phishing campaigns targeting U.S. AI policy experts at think tanks, universities, and law firms. The operation used trust-building outreach followed by a shortened link that redirected victims through checks to a fake Microsoft/OneDrive sign-in…

October 4, 2026
Fake ChatGPT “Custom GPT” Pushes RAT via CAPTCHA

Fake ChatGPT “Custom GPT” Pushes RAT via CAPTCHA

Criminals used sponsored Google search results to promote a malicious ChatGPT “Custom GPT” called “Plus 5.6.” Victims were led to a fake Cloudflare CAPTCHA page that ultimately tricked them into downloading and running a remote access trojan (RAT). This is a realistic web-based lure that can be…

October 4, 2026
China-Linked Phish Uses Fake Gmail Preview

China-Linked Phish Uses Fake Gmail Preview

A China-linked espionage group (UAT-11587) targeted Asian government and policy organizations using highly tailored phishing emails and realistic decoy documents. After a click, malware ultimately installed the “Antino” backdoor, which then hid its command-and-control traffic inside normal…

October 3, 2026
Fake ChatGPT ‘Outage’ Lures Users Into Malware

Fake ChatGPT ‘Outage’ Lures Users Into Malware

Attackers are using sponsored Google ads to route people to a malicious “custom GPT” that looks like ChatGPT, even while the user is logged in on the real ChatGPT domain. The fake GPT displays a convincing “service availability” message and pushes a link to a “backup domain” that ultimately…

October 2, 2026