Skip to content
MarketsIndicesCommoditiesFXRates
Finance

Fake subscription emails with real IBAN data hit French inboxes

Fraudulent emails impersonating a Cellcast Videos streaming service have flooded French inboxes since Saturday, using real names, addresses and IBANs to trick recipients into surrendering bank card details.

Fake subscription emails with real IBAN data hit French inboxes

A wave of fraudulent emails claiming to confirm a subscription to a video streaming service has been circulating since Saturday, using recipients’ real personal data to appear legitimate before directing them to a fake platform designed to steal bank card details.

The emails reference a service called Cellcast Videos and describe a so-called Videos + Family plan billed at 49.99 euros per year. The message tells recipients that following a one-year trial period, their registration is confirmed and a payment is being processed. It then invites them to manage, suspend or cancel the subscription before the upcoming charge.

What makes the emails unusually convincing is that they include the recipient’s real full name, home address and IBAN number. Clicking the management button leads to a platform that offers to cancel the payment and refund 49.99 euros but requires the user to enter full bank card details to do so.

170 reports in three hours

The French online scam-tracking community Signal Arnaques recorded 170 reports within three hours of the emails appearing on Saturday morning and warned that tens of thousands of victims could be affected in total. Screenshots gathered by the site show the fake cancellation platform requesting complete card information.

Cybersecurity forensic expert Thibaut Henin told TF1info that the mechanism itself should raise immediate suspicion. He said that a bank card and an IBAN are two entirely separate things, with an IBAN serving as an address provided to an organisation alongside a mandate signature to authorise a direct debit. Asking for a card number to cancel a SEPA transfer-based subscription, he said, makes no sense, comparing it to producing a driving licence to cancel an identity card.

Fake domains, real company names

The fictional streaming service borrows the Cellcast name from real businesses, including an Australian telecommunications company and a British broadcast group. The fraudulent emails, however, point to two different domains, cellcast-fr.com and cellcast.fr, both of which were inaccessible on Sunday. Registration data from the Internet Corporation for Assigned Names and Numbers shows the first domain was created on Saturday, while the second had already disappeared from the registry.

Signal Arnaques noted that the approach mirrors a phishing campaign reported in March 2025 that falsely announced activation of an Amazon Prime Family service, also using a genuine platform name as cover.

Where the personal data may have come from

How the attackers obtained such detailed personal information remains unclear. According to accounts gathered by Signal Arnaques, some victims are customers of French telecoms operators Free and Bouygues Telecom, which suffered data breaches in 2024 and 2025 respectively, though no official link has been confirmed.

Henin noted that cross-referencing the email address used in the message with a single past provider might offer a clue, but called such connections somewhat coincidental. He also pointed out that water and electricity suppliers also use IBANs for billing, widening the pool of possible sources.

Given the scale of data leaks in recent years, Henin said people must largely accept that once personal information becomes public it cannot be erased, and that stolen databases are often resold by criminals to others, sometimes years after the original breach.

What to do

Henin advised that simply clicking the link in the email carries limited risk on its own, but said it is better not to take even that chance. Deleting the email and staying alert is sufficient, since a leaked IBAN alone does not give fraudsters the ability to withdraw money. He described the IBAN as just an address, saying that without a handwritten signature on a mandate, criminals do not have the key to enter.

Anyone who clicked the link and entered card details should contact their bank immediately to block the card. Henin recommended going straight to the bank as the simplest and most effective step, saying that if a suspicious transaction has occurred a bank adviser can reverse it at once, and if not, the adviser can monitor the account and block any incoming request.

When a data breach is announced by a company, changing the account password for that service is worthwhile. But once a phishing attempt has already occurred without certainty about the source of the leak, Henin said that making changes would be an effort for nothing.

Related

Leave a comment

Your email address will not be published. Required fields are marked *