The Cybernews research team recently discovered a publicly accessible server running a major phishing operation impersonating the French bank Credit Agricole. After discovering the threat actor’s infrastructure, our team contacted Credit Agricole and the French CERT to inform the company and relevant authorities of the abuse.
Here’s what the investigation found:
- The phishing campaign had access to 149 stolen SendGrid API keys and three stolen AWS accounts, with a combined sending capacity of around 7,000 emails per day.
- The phishing panel’s database contained 912 victims who had entered their credentials into phishing forms, as well as 83 payments made to the scammers.
- Bank credentials were used only to obtain additional data on the victim. To scam people out of their money, cybercriminals called the victims and used social engineering techniques to trick them into paying for a fake service.
- The phishing panel contained a leaderboard for the phishing operators to compete against each other to see who could earn the most from their victims. The prize for the most successful scammer was €3,000.
The findings underline a painfully obvious security problem: organizations continue to leave sensitive files exposed in internet-facing systems, unintentionally handing attackers the tools needed to operate fraud campaigns.
For more information, here’s the full report:
https://cybernews.com/security/bizarre-credit-agricole-phishing-scam
Related
This entry was posted on August 5, 2026 at 8:59 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Researchers uncover exposed hacker server revealing details of a major phishing operation, complete with a scammer leaderboard
The Cybernews research team recently discovered a publicly accessible server running a major phishing operation impersonating the French bank Credit Agricole. After discovering the threat actor’s infrastructure, our team contacted Credit Agricole and the French CERT to inform the company and relevant authorities of the abuse.
Here’s what the investigation found:
The findings underline a painfully obvious security problem: organizations continue to leave sensitive files exposed in internet-facing systems, unintentionally handing attackers the tools needed to operate fraud campaigns.
For more information, here’s the full report:
https://cybernews.com/security/bizarre-credit-agricole-phishing-scam
Share this:
Like this:
Related
This entry was posted on August 5, 2026 at 8:59 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.