Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [CRIME]
2 clusters · 9 sources · 10 days · First seen · Last updated
Crédit Agricole phishing campaign
Overview
A sophisticated phishing campaign has targeted customers of Crédit Agricole, France’s largest bank. Attackers utilized stolen SendGrid API keys and compromised AWS accounts to bypass spam filters, enabling the distribution of approximately 7,000 fraudulent emails per day.
The scam employed emails designed to create a sense of urgency, instructing users to ‘renew the registration’ of a trusted device to prevent account lockout. Investigations revealed the infrastructure involved roughly 470,000 server addresses. At least 912 individuals have reportedly provided their banking credentials to the attackers, who then used the stolen login information and passwords in attempts to withdraw funds from the victims' accounts.
Entities
Credit Agricole · SendGrid · Côte-d’Or Gendarmerie · AWS · Cybernews
Timeline
-
26 days ago
[CRIME] 4 sourcesCrédit Agricole customers targeted by sophisticated phishing scamA sophisticated phishing campaign targeting Crédit Agricole customers has defrauded 912 people by using fake websites and legitimate email services to bypass security filters.
-
about 1 month ago
[TECHNOLOGY] 5 sourcesCrédit Agricole customers targeted in major phishing campaignA sophisticated phishing campaign targeting Crédit Agricole customers has compromised at least 912 individuals using stolen API keys to bypass spam filters and conduct social engineering.
Sources
1001web.fr · actu.fr · alagnon-sigal.fr · econostrum.info · letribunaldunet.fr · market-insight.fr · net-wash.fr · nextplz.fr · quechoisir.org