Sophisticated phishing operation ensnares nearly 1,000 Crédit Agricole clients
Nearly 1,000 clients of Crédit Agricole, France's largest bank serving 54 million customers globally, fell victim to an elaborate phishing scheme in June that combined fake websites with phone-based impersonation to steal banking credentials and funds.
The operation, which came to light in early August through technology publications before gaining national attention via RMC, saw fraudsters successfully harvest login details from 912 customers. Of these, 83 individuals subsequently transferred money after receiving convincing phone calls from scammers posing as bank employees.
A growing national threat
The incident reflects a broader crisis in French cybersecurity. Phishing now represents the primary cyber threat for French individuals, accounting for 38% of assistance requests to the government's Cybermalveillance.gouv.fr platform, with 50,000 people and businesses seeking help in 2023 alone. France lost an estimated €4.5 billion to fraud in 2023, with fake bank advisor scams accounting for more than 40% of all digital banking fraud in the country.
According to the U.S. Cybersecurity and Infrastructure Security Agency, over 90% of cyberattacks globally now begin with phishing as an initial attack vector, making it the leading method used by threat actors to breach networks.
The mechanics of deception
The scheme began with mass emails designed to appear as if they came from Crédit Agricole. Fraudsters employed sophisticated mass-mailing software capable of sending approximately 7,000 emails daily, targeting the bank's approximately 27 million retail customers in France across its 39 regional banks.
Recipients received messages with email addresses crafted to closely resemble legitimate Crédit Agricole communications, often using subtle spelling variations or alternative formats that bypassed spam filters. The messages directed victims to meticulously constructed fake websites replicating the bank's official online portal in layout, fonts and imagery, though with different web addresses.
A total of 912 people entered their banking credentials on these fraudulent sites. The increasing sophistication of such attacks is partly explained by technological advances: by early 2026, approximately 82.6% of phishing emails were AI-assisted, a dramatic surge from just 4% in November 2025, enabling scammers to create more convincing messages with improved grammar and personalization at scale.
The second wave
Rather than immediately attempting to access accounts, which would trigger security alerts, the fraudsters waited several weeks before launching the second phase of their operation. Armed with stolen information including victims' local branch details, account balances and the names of personal advisors, scammers placed phone calls impersonating bank staff.
These calls exploited advanced telephone systems capable of masking numbers to appear as if originating from victims' actual local branches. The surge in such voice phishing, or vishing, has been dramatic, with incidents increasing 442% from the first half to the second half of 2024. AI voice cloning technology can now replicate a person's voice from just three seconds of audio, making phone-based scams increasingly difficult to detect.
During these calls, fraudsters warned victims of supposed unauthorized account access and urgently requested password resets or temporary fund transfers to secure accounts. The scammers reportedly maintained a leaderboard, allowing operators to compete for the highest earnings from their targets.
This approach helps fraudsters circumvent security measures while complicating victim compensation claims, as transfers appeared to be authorized by account holders rather than conducted without consent.
Security measures and their limits
Modern banking security includes multiple protective layers. Strong Customer Authentication, introduced under the EU's revised Payment Services Directive in September 2019, requires verification through multiple channels when logging in from new devices or initiating transfers. Since its introduction, fraud on mobile devices has dropped 68% in France.
However, these technical safeguards prove ineffective against social engineering tactics where victims are manipulated into voluntarily providing credentials or authorizing transfers.
Bank response and victim status
Contacted by technology website 01net in August, Crédit Agricole stated that the fraud attempt had been thwarted and concluded two months prior. The bank emphasized that its own security systems had not been breached, characterizing individual clients as the victims rather than the institution itself.
Protecting against sophisticated fraud
Security experts recommend several precautions:
- Carefully verify all incoming email addresses, even those appearing legitimate, by checking them against known official contacts or previous correspondence.
- Avoid clicking links directly from emails or text messages; instead, navigate manually to the bank's website through a browser.
- When following any link, examine the website address for spelling errors or variations indicating a fraudulent site.
- Never provide personal banking information, especially passwords, anywhere except verified official websites.
Banks consistently advise that they never request personal banking details or fund transfers by phone.
If contacted by someone claiming to represent your bank and requesting such actions, terminate the call and contact the bank directly using a number found independently online rather than calling back the number provided. French victims of phone scams in 2026 reported average losses of €628, ranking third highest among surveyed countries after the UK and Germany.
The scale of fraud losses in France remains substantial, with total scam losses reaching €7.6 billion in the 12 months ending June 2025. More than half of French adults surveyed reported falling victim to a scam in the past year, according to research by the Global Anti-Scam Alliance and BioCatch.






