How a complex fraud caught out 1,000 clients of major French bank

Scammers ‘phished’ for information about Crédit Agricole customers’ local branches and then posed as staff

Victims initially entered personal details on fake website
Published Modified

Nearly 1,000 clients of one of France's main banks, the Crédit Agricole, have had their banking details taken as part of a sophisticated phishing campaign, it has been revealed.

Victims were encouraged to enter details about their account via a fake but official-looking email that directed them to a website mimicking the bank’s official online space. 

This information was then used by scammers to pose as employees of the victim’s local branch in follow-up calls, where around 83 people were further tricked into sending money from their account. 

It has led to calls for increased vigilance over online scams, particularly coming from seemingly-trusted sources. 

How did scam work? 

The operation, carried out in June, was reported by several tech websites in early August before being picked up by national outlet RMC. 

With these types of scam, fraudsters begin by choosing a major and trusted company or group to mimic, typically a bank or financial institution.

“What this means for scammers, especially in the phishing game, is a big name, with plenty of potential customers to victimise,” said media outlet Cybernews about the operation. 

Once a company is chosen, the scammers set up a mass email system with an email address that looks like it comes from the original company they are pretending to be.

Email addresses will look similar to official ones used, but with a slightly spelling difference or using a different format. 

Scammers employed sophisticated software used by major companies to send out mass emails.

“To put it simply, it’s one of those “donotreply@trustedcompany.com” emails most of us have received numerous times from service providers we trust" used in the scam, adds Cybernews.

Because of the convincing look of the email address, these are often not flagged as spam and enter into your main email inbox, further strengthening their legitimacy.

Fraudsters can send out around 7,000 emails per day using mass emailing software, and with a pool of roughly 21 million Crédit Agricole clients, can keep the system running for extended periods. 

Fake emails can come with a variety of requests – to change passwords or account information, a fraudulent notification about someone accessing your account, etc – but all aim to lead people to a fake website. 

These websites are designed to mimic the official company scammers are posing as, copying the layout, font, photos, etc on the site. However, the website address (URL) will be different. 

In the scam above, users were directed to a fake website and asked to enter their bank log-in details to confirm they still had control of their account. 

A reported 912 people entered their details this way.

Two-pronged attack

This is only the set-up of the scam, however, which uses a two-pronged approach. 

Banks have a series of additional security measures in place to prevent breaches. 

For example, if someone logs into an account from a new device - such as a scammer who has taken your log-in details using their own computer - and tries to send money to a different account, the request typically needs to be verified in the phone app, alerting the would-be victim.

Other cases of two-factor authentication such as text messages or emails also help reduce the risk of scammers directly attacking accounts this way.

Rather than using this information to directly empty a victim’s bank account, scammers therefore took details about the victim – their local branch, name of their personal bank adviser,  account balance, etc – so they could pose as staff from the location.

They wait a few weeks, then call the victim pretending to be from the branch, using the information stolen in the initial breach to earn trust and legitimacy. 

This can be combined with advanced telephone systems that can mask numbers and even re-direct calls to look as if they are coming from your local branch or personal adviser directly.

Scammers using this method will typically call with a fake warning about the victim’s account, usually that someone else is trying to access it, and telling you that you urgently need to reset your details. 

They will then ask you for your sensitive information, such as account passwords, etc, or ask you to temporarily transfer funds directly to another account. 

In the above scam, around 83 victims gave away funds this way. 

The scammers also allegedly had “a leaderboard allowing phishing operators to compete against one another to see who could earn the most by exploiting their victims,” reports Cybernews.

Scammers typically use this trick not only to gain legitimacy and increase their chances of taking information, but also because in these instances, victims are seen as willingly handing over the funds. 

This makes it harder for authorities to investigate scammers, however, it also makes it more difficult for victims to claim compensation or a refund from their bank, as they were informed about the transfer in advance and funds were not transferred without their consent.

Tell-tale signs to look out for

Contacted by technology website 01net in August, Crédit Agricole said “the fraud attempt was thwarted and has been over for two months.”

The bank said it was not a victim of fraud itself – as its own security systems had not been breached – but that individual clients were victims. 

Clients should therefore be extra vigilant, as they are being directly targeted. 

Standard advice regarding anti-scam safety remains paramount:

Carefully check the address of all incoming emails, as even if they look like a legitimate address this may not be the case. Check online to see if such an email address is legitimate, or if you have received an email from that exact address before. 

Do not click on any links directly from an email or text – open your browser and head to the bank website yourself and log-in directly this way. 

If the request is legitimate, you should be able to find the corresponding link through your personal space this way. 

If you do click on a direct link through your email, check the website address (URL) to ensure there are no spelling errors showing this is a fake website. Again, these fake sites are extremely sophisticated and can look identical to the ones scammers are posing as. 

Do not hand out personal information about any account – especially passwords – anywhere except the official website. 

Banks continually advise customers that they never ask for personal banking information on the phone, nor ask people to make transfers, etc, in a call. 

If someone calling you asks you to do so, hang up and call your bank’s customer service or local branch directly. Do not simply call back the number that has called you, but find the number online, to ensure you reach the bank and not a scammer.