Complex fraud catches out 1,000 clients of major French bank
Nearly 1,000 customers of Crédit Agricole, one of France's largest banks with over 21 million retail clients in the country, fell victim to a sophisticated phishing campaign in June that combined fake emails with fraudulent phone calls posing as bank staff.
The operation, which was discovered by cybersecurity researchers on June 19 when they found a publicly accessible server running the phishing infrastructure, led to 912 people entering their banking credentials on a fake website designed to mimic the bank's official online platform. Of those, 83 customers were subsequently tricked into transferring money directly to the fraudsters.
Advanced infrastructure bypassed security filters
The scammers deployed unusually sophisticated technical methods to make their operation appear legitimate. Attackers used 149 stolen SendGrid keys and three Amazon Web Services accounts to send phishing emails through trusted infrastructure, allowing them to bypass spam filters that would normally flag such messages as fraudulent.
This technical approach enabled the fraudsters to send approximately 7,000 emails per day using mass emailing software that mimicked the format of legitimate bank communications, complete with official-looking "donotreply@trustedcompany.com" style addresses.
The initial emails directed recipients to a fake website where they were asked to enter their login details under the pretext of confirming control of their account. The fraudulent site replicated the layout, fonts and visual elements of Crédit Agricole's genuine online banking portal, though the website address itself was different.
Two-stage attack exploited security measures
Rather than attempting to access accounts directly with the stolen credentials, which would trigger two-factor authentication systems and alert victims, the scammers used the information to prepare for a second phase of the attack.
The fraudsters harvested details about victims' local branches, personal bank advisors and account balances. Several weeks after the initial phishing emails, they called victims pretending to be staff from their specific branch, using the stolen information to establish credibility.
These follow-up calls employed advanced telephone systems that masked numbers and even redirected calls to appear as if they were coming from the victim's local branch or personal advisor. Scammers typically warned that someone else was attempting to access the account and requested that victims urgently transfer funds to a different account for safekeeping.
The operation allegedly included a leaderboard allowing participants to compete against one another to see who could extract the most money from victims.
Part of broader fraud epidemic in France
The Crédit Agricole incident reflects a wider pattern affecting French consumers. Phishing reports in France reached 1.6 million in 2025, representing a 33% increase compared to 2024, with estimated financial losses totaling €310 million.
Banks are the primary target, with 28% of phishing attempts in France impersonating financial institutions such as Crédit Agricole, BNP Paribas and Société Générale. Fake bank advisor scams accounted for 43% of all digital banking fraud in France in 2023, with average losses of €29,000 per victim.
The threat environment has intensified in recent months. In February 2026, France experienced a major breach when 1.2 million bank accounts from the FICOBA national registry were exposed after attackers stole credentials from a civil servant.
French banks collectively lose an average of €4.2 million to fraud annually, with 79% of banking executives believing their institutions lose over $5 million each year to fraudulent activity.
Why the scam succeeded despite protections
Modern banking security measures, including Strong Customer Authentication implemented under the EU's Payment Services Directive, have reduced fraud on mobile devices by 68% in France since September 2019. These protections typically require verification through phone apps or text messages when logging in from new devices or initiating transfers.
However, the two-stage nature of this scam circumvented these safeguards by convincing victims to voluntarily authorize transfers. Because customers were informed about the transactions in advance and gave consent, albeit under false pretenses, it becomes harder for authorities to investigate and more difficult for victims to claim compensation from their banks.
Bank response and customer warnings
Contacted by technology publication 01net in August, Crédit Agricole stated that the fraud attempt was thwarted and had been over for two months. The bank clarified that it was not itself a victim of a security breach, but rather that individual clients had been targeted.
Security experts advise customers to carefully examine all incoming email addresses, avoid clicking links directly from emails or text messages, and instead navigate to banking websites manually through a browser. Bank websites should be accessed by typing the address directly rather than following embedded links.
If a link is clicked, customers should verify the website address for spelling errors indicating a fake site. Banks never ask for personal information or passwords over the phone, nor do they request transfers during phone calls. Anyone receiving such requests should hang up and contact their bank's customer service or local branch directly using a number found independently online, rather than calling back the number that initiated the contact.






