The Crédit Agricole Phishing Attack That Used Stolen Email Infrastructure
Cybersecurity researchers have uncovered a sophisticated phishing campaign targeting clients of Crédit Agricole, France's largest bank. By breaking into legitimate email delivery services, attackers were able to send over 7,000 fraudulent messages without triggering spam filters. These emails, disguised as a mandatory re-registration of a trusted device, tricked 912 account holders into entering their banking credentials on a fake website that closely mimicked the real Crédit Agricole portal.
But the scam did not stop there. Armed with the login details, the criminals exploited an even deeper layer of personal data visible after accessing accounts—such as the victim’s branch name, their advisor’s name and the actual account balance. Using this information, they called victims directly, posing as bank representatives who could quote these private details to build trust. That social engineering step convinced 83 individuals to make payments to the scammers, often under the guise of a fake service or verification fee.
The investigation, conducted by Cybernews and reported by France’s 01net.com, reveals that the attackers had previously scanned 470,000 servers to find accessible keys for trusted email platforms like SendGrid and Amazon Simple Email Service. With these credentials, they engineered a delivery system that made their phishing emails appear legitimate. The group reportedly involved seven individuals, who competed for a “top employee” bonus of €3,000, indicating an organized, incentivized operation. Crédit Agricole stated that the fraud did not breach its own systems but acknowledged that its customers were targeted; it remains unclear whether the criminals are still active.
Inside the Scam: Why Even the Most Cautious Bank Customers Fell Victim
How Stolen Email Legitimacy Bypassed Defences
The scammers' first smart move was to avoid the usual telltale signs of phishing. By using genuine, high-reputation email sending services that had been compromised, the messages sailed through anti-spam filters. For a recipient, an email from a known sender like “[email protected]” or a believable address is far harder to question—especially when it appears to come from the bank’s own infrastructure. This technique is rare in consumer-level fraud and shows a professional understanding of corporate email security.
From Credential Harvesting to Voice Fraud
The real damage multiplier came from the attackers’ ability to talk to victims over the phone using specific banking information. Most people are rightly suspicious of a cold call. But when the caller can confirm your exact account balance, the name of your personal advisor, and even your local branch, they sound immediately credible. This form of “vishing” (voice phishing) is particularly dangerous because it exploits the trust we place in personalised service—and the shock many feel when their private details are recited back to them. The fact that 83 individuals actually sent money suggests the ruse was very convincing.
How to Protect Your Crédit Agricole Account from This Specific Fraud
- Never trust an unsolicited email asking you to “re-register” a device or verify your account. Crédit Agricole does not ask for confidential credentials via links in emails. If in doubt, log in directly by typing the bank’s official website address into your browser.
- Check the sender address carefully. Even if an email appears to come from a known service, examine the full email header. The attackers used hijacked legitimate sending services, so the display name might look correct even if the source is spoofed.
- Over the phone, be ruthless about verification. Before sharing anything, ask the caller for a reference number you can verify through your usual contact method—the official phone number printed on your bank card or statement, not a number the caller gives you.
- Remember that real bank calls never require payment. If a person claiming to be your advisor asks for a money transfer, a code from a authentication app, or a payment to “unblock” your account, it is a fraud. Hang up and call the bank yourself.
Comments 0