A sophisticated Credit Agricole phishing operation used stolen email-service credentials, exposed cloud files, and carefully planned phone scams to steal from bank customers.
Researchers uncovered the campaign on June 19 after finding a publicly accessible server used to run the fraud operation. The phishing infrastructure contained records for 912 people who submitted their banking credentials and 83 payments made to the scammers.
The attackers impersonated Credit Agricole, one of Europe’s largest financial institutions. By using legitimate business email infrastructure, they made fraudulent messages harder to identify and block.
Researchers notified Credit Agricole and the French CERT after discovering the operation. The bank and relevant authorities were contacted for comment.
Attackers Used Stolen Email Credentials
The Credit Agricole phishing campaign began with the theft of credentials linked to legitimate email delivery services.
According to the researchers, the criminals searched exposed Amazon cloud storage buckets for sensitive files. They looked for environment files, database backups, Python configuration files, and Vim swap files that could contain SendGrid or Amazon Simple Email Service credentials.
Businesses commonly use SendGrid and Amazon SES to send large volumes of legitimate email, including invoices, password resets, marketing campaigns, and service notifications.
This made the stolen keys particularly valuable. Instead of sending phishing emails from suspicious servers, the attackers could use trusted business infrastructure. As a result, their messages were more likely to reach inboxes and appear legitimate to recipients.
At the time of the investigation, the operation held 149 stolen SendGrid API keys and three compromised AWS accounts. Together, the accounts could send around 7,000 emails per day.
The attackers first tested the stolen accounts to identify their sending limits and subscription tiers. This helped them decide which services could distribute the largest phishing campaigns.
Criminals Built a Large Target List
The group did not rely on a simple purchased mailing list. Instead, researchers found that the attackers mapped internet infrastructure in several stages.
They began with a seed list of 220,000 IP addresses known to host websites. Then, they searched nearby addresses within the same network ranges and discovered another 250,000 IP addresses.
Next, the attackers linked those addresses to domains through DNS lookups and SSL Certificate Transparency logs. They also added information from the world’s top one million domains.
This process gave the criminals a broad pool of potential victims, while also helping them identify organisations that would make convincing impersonation targets.
The scammers later filtered out cloud providers, corporate static IP ranges, and generic virtual private servers. Researchers believe this may have helped them avoid security honeypots and reduce the chances of detection.
They then scanned targets for exposed configuration files while sending phishing emails to employees. The employee contact details were likely obtained through commercial business intelligence platforms.
This dual approach gave attackers two possible routes into a target. An organisation could expose technical secrets through poorly secured cloud resources, while its employees could become victims of the Credit Agricole phishing scam.
Stolen Bank Credentials Helped Scammers Prepare Calls
The phishing email seen by researchers was written in French. It urged recipients to renew the registration of a trusted device or risk losing access to their account.
Although that message may appear suspicious on its own, it becomes far more convincing when it arrives through an email address linked to a legitimate business service.
The fake banking pages collected victim credentials. However, the attackers did not immediately use those details to make obvious fraudulent transactions.
Instead, the phishing panel automatically logged into victim accounts and gathered additional information. This included the account balance, local branch name, and the name of the customer’s bank adviser.
The researchers believe the information helped criminals identify valuable targets and make later phone calls sound more credible.
Rather than relying only on stolen credentials, the group used social engineering to persuade victims to pay for a fake service. Knowing a customer’s branch, adviser, and account balance could make a caller appear far more believable.
Phishing Operators Competed for Victim Payments
The operation also included a leaderboard for phishing operators. Researchers found that the panel supported several users, with seven accounts registered during the investigation.
The system encouraged scammers to compete over who could earn the most money from victims. Screenshots of the dashboard showed that the prize for the most successful operator was €3,000.
The campaign shows the industrial scale of modern financial fraud. The attackers combined cloud-secret scanning, stolen email infrastructure, internet mapping, employee targeting, credential theft, and phone-based social engineering in one operation.
People who entered their details into the phishing pages could face account takeover, fraudulent payments, and follow-up scams. Meanwhile, businesses whose cloud or email credentials were abused may face reputational damage, service disruption, and further compromise if more secrets remain exposed.
The case also highlights a persistent problem for organisations: exposed configuration files and credentials can give criminals the infrastructure they need to launch convincing fraud campaigns.


0 responses to “Credit Agricole Phishing Scam Used Stolen Email Keys and Fake Calls”