INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Revolut Customers Targeted with New Wave of Phishing Attacks

| 2026-10-01 11:30 CRITICAL MEDIUM PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A phishing campaign targeting Free Mobile customers in France appeared after a data breach, with convincing emails that closely copied the company's official website and email templates. The attackers used a link to redirect users to various domains hosted by Cloudflare, which were registered just a month ago, including [IOC HIDDEN • LOGIN REQUIRED]. One employee received such an email on September 30, prompting the company to warn its customers about the scam. To stay safe, Free Mobile advises treating unexpected messages with caution and not following links in unsolicited emails; instead, users can open the official app or website directly or call the help line at 3244.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
s•••••.ink
bl•••••.to
re•••••.fr
mo•••••.fr
fr•••@kn•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
IT FR
cryptocurrencycryptocurrency financefinance
Incident Timeline
‎October 2024
Threat actors used convincing phishing emails to target Free Mobile customers after the October 2024 data breach.
organisation Malwarebytes Browser Guard
organisation Cloudflare
organisation Free Mobile
organisation Malwarebytes Scam Guard
‎September 14
Threat actors sent convincing free mobile phishing emails to victims just two days after a bank acknowledged a data breach.
‎Wednesday, September 30
Threat actors sent convincing phishing emails to a Free Mobile customer after the company's data breach.
tactic Phishing
‎2026/10/01
Threat actors impersonated Italian law enforcement to compromise email accounts and send convincing phishing emails targeting Revolut customers.
organisation CNIL
financial €27 providers
organisation Revolut Customers Targeted
organisation Revolut
organisation Revolut Customers Urged
organisation European Investigation Orders
organisation KYC
organisation Interior
Tactical Metrics
Metrics
financial
27,000,000
Providers
Intelligence Sources
Infosecurity-Magazine 2026-09-21