logo

The French 2-Step: Exposing a Multi-stage Scam Targeting the National Railway Company in France

ID: 94d1399b-7a6a-5c04-b200-f5830971a55b

STIX ID: report--94d1399b-7a6a-5c04-b200-f5830971a55b

Feed Name: Group-IB Blog

Threat Score
60/100

Date Published: 2026-05-13

Date Updated: 2026-05-14

...
...

Group-IB details a multi-stage scam targeting SNCF customers in France: attackers use leaked personal data to send timely phishing emails and host convincing fake SNCF websites that accept payments via legitimate processors (such as Stripe), then follow up with phone calls impersonating bank counselors to obtain IBANs, security codes, and authorize further fraudulent transactions. The report includes indicators of compromise (domains, email addresses, phone numbers), victim testimonials, analysis of attacker tactics and timing (aligned with French school holidays), and mitigation recommendations for organizations and individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.