Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsA Free Mobile phishing email reported on 30 September 2026 claimed a €9.99 invoice was unpaid and threatened service suspension. Malwarebytes described a lookalike payment page seeking card details. The email is a reported sample, not proof of a widespread campaign—and available sources do not establish that it used information stolen in Free’s confirmed 2024 data breach.
What the reported Free Mobile email said
Malwarebytes Labs reported that an employee who is a Free Mobile customer received the email on 30 September 2026. It used Free branding and templates, claimed an invoice of €9.99 was unpaid, and urged payment to avoid suspension. The message had a suspicious sender address and links that redirected to a lookalike Free Mobile payment page requesting card details. Malwarebytes called it more convincing than earlier Free Mobile scams it had seen.
This account comes from one security-vendor report, published on 1 October 2026; it does not show how many customers received the message or whether every reported indicator is still active. One reported final destination was espace-free-mobile.pro, a domain Malwarebytes said had been registered about a month earlier. Treat domains and redirect paths as time-sensitive indicators, not as links to test by visiting.
What is known about the Free data breach
The breach occurred in October 2024. CNIL’s 14 January 2026 announcement said an attacker accessed personal data relating to 24 million subscriber contracts. CNIL also said IBANs were included for people who were customers of both FREE MOBILE and FREE, and that it had received more than 2,500 complaints from affected people before its inspection. On 13 January 2026, CNIL’s restricted committee fined FREE MOBILE €27 million and FREE €15 million, €42 million in total. CNIL’s announcement gives the regulator’s account of the incident and decision.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Not every affected person had the same information exposed. Cybermalveillance.gouv.fr lists categories that include names, email and postal addresses, date and place of birth, phone numbers, subscriber identifiers, and contract details. For some people, bank-account references or an IBAN were involved. The agency says passwords were not believed to have been affected. See its Free breach guidance for the risks and recommendations.
The chronology does not establish a link between the breach and this email. The breach is confirmed, and Malwarebytes reported the later phishing sample, but the reviewed sources do not show that the sender used data taken in 2024. A message that appears tailored can still have another source.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to check a Free invoice or account message
Do not decide that a message is genuine just because it looks polished or carries familiar branding. Instead, assess the request and verify it through a separate route:
- Pause at pressure or sensitive requests. An urgent demand to pay to avoid suspension, or a request for card details, passwords, or security codes through an unsolicited message, warrants caution. These are warning signs, not a complete test of authenticity.
- Check the actual sender and destination. Malwarebytes described an unrelated sender address, redirects, and a lookalike payment site in this sample. Do not follow its links to investigate, and do not treat a convincing logo or layout as proof.
- Open Free independently. Type Free’s official address yourself or use its official app, then check your account and any invoice there. Free’s guidance points customers with doubts to support at 3244; confirm contact details on Free’s current official site. Free also notes that an additional authentication step for the subscriber area may send a six-digit code by SMS or email. Never give that code to someone who contacts you.
Free’s advice on phishing is available at its official assistance page. For a suspicious message, CNIL’s general advice is not to open attachments, reply, or click login links, and to delete it; see CNIL’s breach guidance.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If you already clicked or entered information
- If you entered card or bank information: contact your bank using the number or app you independently know to be official, explain what you submitted, and follow its instructions.
- If you entered account information or a password: contact Free through independently verified official channels and ask what protective steps apply to your account. Do not use contact details from the suspicious email.
- If you only opened the message: do not continue through its links or attachments. Delete it and verify any claimed invoice by opening Free’s site or app independently.
The cited official guidance does not give a recovery procedure specific to this reported campaign, so the appropriate response depends on what information was shared and the instructions from Free or your bank.
Quick Recap
Rank #4
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

