Researchers uncover exposed hacker server revealing details of a major phishing operation, complete with a scammer leaderboard

The Cybernews research team recently discovered a publicly accessible server running a major phishing operation impersonating the French bank Credit Agricole. After discovering the threat actor’s infrastructure, our team contacted Credit Agricole and the French CERT to inform the company and relevant authorities of the abuse.

Here’s what the investigation found:

  • The phishing campaign had access to 149 stolen SendGrid API keys and three stolen AWS accounts, with a combined sending capacity of around 7,000 emails per day.
  • The phishing panel’s database contained 912 victims who had entered their credentials into phishing forms, as well as 83 payments made to the scammers.
  • Bank credentials were used only to obtain additional data on the victim. To scam people out of their money, cybercriminals called the victims and used social engineering techniques to trick them into paying for a fake service.
  • The phishing panel contained a leaderboard for the phishing operators to compete against each other to see who could earn the most from their victims. The prize for the most successful scammer was €3,000. 

The findings underline a painfully obvious security problem: organizations continue to leave sensitive files exposed in internet-facing systems, unintentionally handing attackers the tools needed to operate fraud campaigns.

For more information, here’s the full report: 

https://cybernews.com/security/bizarre-credit-agricole-phishing-scam

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading