Crédit Agricole Phishing: Anatomy of an Industrial-Scale Fraud Campaign
A criminal operation of rare sophistication has just exposed the inner workings of a banking fraud aimed at France’s largest bank. Here is how a remarkably effective machine was built.
This article will also interest you: A phishing campaign against PayPal users
On June 19, 2026, the cybersecurity research team at Cybernews found a publicly accessible server. Inside was a complete infrastructure dedicated to impersonating Crédit Agricole. This was not a simple spam run: it was a digital war machine, designed, structured, and optimized to trap thousands of the bank’s customers.
With revenue above $45 billion and about 160,000 employees, Crédit Agricole is a prime target for cybercriminals. Its base of 21 million customers is an almost inexhaustible pool of potential victims. Beyond the target, the method is what stands out. Behind the scam sits an organization worthy of a real company, with its processes, its tools, and even its bonus system.
A precision mechanism to bypass defenses
The attackers behind this campaign are clearly not amateurs. They know that a fraudulent email sent from a suspicious server almost always lands in spam filters. To get around that barrier, they adopted a highly effective strategy: hijacking the infrastructure of legitimate companies.
Their method was to methodically scan unprotected Amazon cloud buckets for environment files, database backups, Python configuration files, and even Vim swap files containing API keys. Those keys — SendGrid and AWS SES — belong to perfectly reputable companies that use them every day to send invoices, notifications, and marketing emails.


Once they had the keys, the attackers did not rush. They first assessed the rate limits and subscription tiers tied to each compromised account, determining which hijacked services offered the greatest sending capacity. At the time of the investigation, the campaign held 149 stolen SendGrid API keys and three AWS accounts, for a combined capacity of about 7,000 emails a day. Sent from trusted infrastructure, those messages sailed through spam filters and landed directly in primary inboxes.

Targeting: a meticulous map of the French internet
Where this campaign differs sharply from ordinary phishing is in how the target list was built. There was no email database bought on the dark web. The attackers built their own map.
The starting point was a list of 220,000 IP addresses known to host websites. From there, they scanned adjacent subnets and discovered 250,000 new addresses. Those addresses were then linked to domain names through DNS lookups and SSL certificate transparency logs, then enriched with the world’s top 1 million domains.
The approach has a double advantage. It greatly widens the pool of potential victims. It also lets the attackers identify exactly which companies to impersonate so they look credible to their targets. Final filter: cloud hosting platforms, corporate static IPs, and generic virtual private servers were removed — probably to avoid honeypots deployed by security companies.
The so-called “dual-track” approach shows the ingenuity of the setup: the targeted companies were not only pools of potential banking victims, but also potential sources of extra infrastructure and intelligence. A targeted organization could therefore help the attackers in two ways at once: by supplying exposed technical secrets, then by supplying employees who could be lured to fake banking pages.
The trap: a credible email, a chilling phone call
The phishing email, written in French, plays on a well-tested psychological trigger: security urgency. It asks recipients to “renew the registration” of a trusted device or lose access to their bank account. On its own, the message could look suspicious. But when it comes from a legitimate sending address — or at least one that appears legitimate — suspicion collapses.
The link in the email redirects to a faithful copy of the Crédit Agricole website. Victims enter their credentials with confidence. At the time of the investigation, 912 people had taken the bait.
Credential theft was only the first step. Analysis of the phishing panel’s backend shows a formidable automation: the stolen credentials were immediately used to extract extra information about the victim’s account:
- remaining balance;
- name of the local branch;
- name of the assigned bank adviser.
That data then let the scammers move up a level: the fraudulent phone call. A few hours after entering their information, victims received a call. The displayed number matched their bank branch. On the line, a caller who knew their balance, their adviser’s name, and their branch. Everything looked legitimate. The scammers then pushed their victims to make a payment for a supposed security service. 83 fraudulent payments had been recorded at the time of the investigation.
A very corporate criminal organization
The most troubling detail in this case may be the criminal group’s internal organization. The phishing panel did not merely run campaigns: it ranked the operators against each other.

“The phishing panel also contained a leaderboard that let phishing operators compete over who could earn the most by exploiting their victims,” the researchers explain. At the time of the investigation, seven operator accounts were registered. The prize for the most successful scammer was €3,000.
This reward system, modeled on the motivation mechanisms of legitimate companies — employee of the month, performance bonus — shows how professional cybercrime has become. The attackers are no longer isolated individuals working in the shadows: they are structured teams, with numerical targets, incentive systems, and a logic of profitability.
What this case reveals
For victims, the risks are considerable: account takeover, fraudulent transactions, and cascading social-engineering attacks. For companies whose cloud credentials were abused, the consequences include reputational damage, service disruption, and continued exposure if other secrets remain accessible.
Beyond the direct victims, the case highlights a systemic problem: French organizations continue to leave sensitive files exposed in systems reachable from the internet, unintentionally handing attackers the tools they need to run large-scale fraud campaigns.
Crédit Agricole was informed of the situation, as was the French CERT. The bank was careful to qualify the scale of the attack, saying it was not the company that was targeted, but “possible customers.”
How to protect yourself
Against a threat of this scale, individual vigilance remains the first line of defense. These are the essential reflexes to adopt:
- Always check the sender. An email from Crédit Agricole always comes from an address ending in @credit-agricole.fr. Watch for subtle variants: an extra “s,” a slightly altered domain.
- Never click a link in a banking email. Go to your bank’s website by typing the address into your browser, or use the official mobile app.
- Crédit Agricole will never ask for your codes by email or by phone. Not your password, not an SMS code, not your full banking details.
- Be wary of incoming calls. Even if the displayed number matches your branch, hang up and call your adviser’s official number yourself.
- When in doubt, contact your branch. A verification call is better than a fraudulent payment.
This phishing campaign against Crédit Agricole is not an isolated incident. It foreshadows a new generation of attacks: more sophisticated, more industrialized, and harder to detect. The combination of stolen legitimate infrastructure, methodical target mapping, and monetization through social engineering creates a formidably effective model. For financial institutions and their customers alike, awareness is urgent.