Skip to content

Bringing you global stories from a neutral view

Technology

Phishing Scam Uses Real IBANs to Fake Subscriptions

A phishing scam using victims' real IBANs, names and addresses has tricked people into revealing bank card details since August 1, 2026.

Phishing Scam Uses Real IBANs to Fake Subscriptions

A phishing campaign that began on August 1, 2026, has been tricking recipients into believing they had signed up for an expensive subscription they never requested, using emails that include each victim's real IBAN, name and home address, according to the French news outlet 20 Minutes.

The scammers tell recipients to hand over their bank card details in order to cancel the supposed subscription before the first payment is taken. The campaign has already been reported more than 170 times in three hours on Signal Arnaques, a French platform where internet users flag and search reports of suspected fraud, and is believed to have caused several tens of thousands of victims.



A fake streaming service used as bait

To lend the emails credibility, the fraudsters pose as a service called Cellcast Vidéos. According to the broadcaster TF1 Info, the platform does not actually exist, although the name has previously been used in other contexts by genuine Australian and British media companies.

What sets this campaign apart, 20 Minutes reported, is how well thought out it is. The emails do not rely on guesswork: they include each recipient's correct first and last name, their real home address and their IBAN, the code that identifies a specific bank account for transfers across Europe.

Scammers create a false sense of urgency

The emails warn recipients that they are about to be charged 49.99 euros for a subscription to a "Vidéos + Family" offer. To stop the payment, the message says, recipients only need to click a link and suspend or cancel the subscription before the debit goes through.

Les cybercriminels disposent du véritable IBAN de chaque victime. (illustration)
Fraudsters have obtained victims' real IBANs. (illustration) - Photo: Markusspiske / Pixabay

That link leads to a fake platform, which likewise promises to cancel the charge and refund the 49.99 euros, but only after the user submits sensitive personal data.

It is, of course, a trap. Handing over that information later lets the scammers withdraw money directly from victims' bank accounts. Fraud campaigns of this kind typically combine details harvested from earlier data leaks with a tight deadline, a tactic designed to push recipients into acting before they can check whether a message is genuine.

Legitimate services never require bank card details to cancel or suspend a subscription. Anyone unsure whether they are really subscribed to something should go straight to the provider's official website without clicking the link in the email, or contact their bank directly.

How scammers got hold of victims' bank details

People caught up in the scam are being urged to contact their bank urgently to block any further payments. Investigations are under way to establish how the fraudsters obtained the IBANs of so many victims in the first place.

Investigators believe the data may have come from earlier data breaches at the French telecoms operators Free and Bouygues Télécom, two of the country's largest mobile and internet providers, both of which have previously disclosed security incidents affecting customer records.

An IBAN, short for International Bank Account Number, is a standardised code used to identify a bank account for payments and transfers within Europe. The leak of an IBAN on its own, however, does not pose a direct risk to a victim's bank account, since it cannot be used alone to withdraw funds without further personal or card data.

Related

Leave a comment

Your email address will not be published. Required fields are marked *