A Free Mobile bill for €9.99 can look routine enough to pay without thinking. In a phishing email documented by researcher Jérôme Boursier, that small overdue balance was the reason to leave the inbox, follow a disguised link and hand a fake payment page the details of a bank card. The September 30 sample was received by a Free Mobile customer working at Malwarebytes; the investigation was published on October 1.[1]
The immediate check is simple: open your usual Free app or type mobile.free.fr yourself and inspect the account there. A debt mentioned in an email needs confirmation in the account, rather than payment through the email’s button.
The logo was familiar. The sender was not.
The captured message threatened service restrictions unless the customer settled the bill. Its Free branding helped present the request as account maintenance, but the actual sender used knowledgegrowthcenter[.]help. The visible payment link displayed a Free-looking address. Boursier’s investigation found that following it instead crossed a short-link service and reached espace-free-mobile[.]pro.[1]
Recognition pattern: a Free Mobile display name; sender freemobile-regularisation [at] knowledgegrowthcenter [dot] help; a generic customer greeting; an unpaid €9.99 balance; and a request to settle it promptly to prevent service restrictions. The published crop does not show a subject line.

These are three separate identity checks: the company named in the message, the address sending it and the site receiving the payment. Agreement between the logo and the email’s wording does not establish agreement between those systems. The original screenshot also contains an email-authentication warning; it is a warning shown in this sample, not a promise that every mailbox will flag the campaign.
Free’s own assistance page lists [email protected] for mobile-subscriber emails. It advises checking links and going directly to the subscriber account when a message is doubtful.[2] A matching display name alone would still be insufficient: the destination and the account’s actual billing state matter.
The €9.99 debt became a card-data request
The endpoint copied a subscriber-payment page and asked for bank-card details. The researcher also documented other lookalike domains, including freesas[.]info and regularisation-free[.]info.[1] Those names are recognition clues from the investigation, not a complete blocklist or addresses to visit.

The useful distinction is between the small amount claimed and the information requested. A page collecting a card number, expiry and security code is asking for reusable payment credentials; its potential consequence is not limited to the €9.99 written on the invoice. The published evidence shows the collection form, not a count of victims or a verified total of fraudulent charges.
That is the same trust failure illustrated by the bpost small-fee phishing case: a modest bill can make a sensitive-data request feel proportionate. Checking the account independently breaks the link between the plausible story and the attacker’s form.
The older breach does not prove this email’s origin
Free’s October 2024 data breach is relevant background. France’s government cyber-assistance service lists customer contact and account information, including IBANs for some people, among the exposed data; it says passwords were reportedly unaffected.[3] This does not establish that the senders of the September 30 email obtained its recipient from that breach. The new development is the documented phishing sample and payment chain, not a newly announced Free breach.
If you entered card details, contact your bank through its usual app or the number on the card and report the exposure. Preserve the message and screenshots. If you also supplied account credentials, change them through the independently opened official account. Merely receiving this email does not demonstrate device infection.
The decisive mismatch is the handoff: a familiar operator’s billing story sends payment information to a different domain. The logo, fluent French and small balance do not repair that mismatch.
References
- Jérôme Boursier. “Convincing Free Mobile phishing emails appear after data breach.” Malwarebytes Labs, October 1, 2026. Primary investigation.
- Free. “Emails, SMS et appels indésirables : comment se protéger contre les tentatives de phishing ?” Assistance Free, accessed October 2, 2026. Official phishing guidance.
- Cybermalveillance.gouv.fr. “Violation de données personnelles de l’opérateur Free : situation, risques et recommandations.” October 31, 2024; updated August 10, 2026; accessed October 2, 2026. Breach scope and recommendations.

