started · updated
Crédit Agricole customers targeted by sophisticated phishing scam
A sophisticated phishing scam has targeted Crédit Agricole customers, resulting in 912 victims providing their credentials on a fraudulent website. The attackers used emails designed to create a sense of urgency, instructing users to ‘renew the registration’ of a trusted device to avoid losing account access.
To bypass spam filters, the cybercriminals utilized legitimate email services such as SendGrid and Amazon Simple Email Service. Investigations revealed that the infrastructure involved approximately 470,000 server addresses, allowing for the distribution of over 7,000 fraudulent emails daily. The attackers used the collected login information and passwords to attempt to withdraw funds from the victims' accounts.