Crypto Fraud in France: Inside the Data Chain Behind the Attacks

What happened in Jouy-en-Josas, and why does it frame the whole report?

On 24 August 2026, three individuals entered a home in Jouy-en-Josas, in the Yvelines, and held its occupant for approximately two hours in order to obtain access to his crypto accounts. They had arrived expecting to extract the equivalent of six million euros, while the accounts they were shown held around three thousand. The facts were reported by national and local press, and the investigation was entrusted to the Versailles anti-gang unit.

No link to any identified data breach has been established at this stage, but the gap between assumed wealth and actual wealth is precisely what makes the case instructive. It demonstrates the mechanism the rest of our investigation documents, which is that the data driving an operation of this kind only has to exist and circulate, never to be correct.

How mature is crypto fraud in France?

Our investigation identifies four specialised roles operating in sequence, covering acquisition, brokerage, exploitation and monetisation, with a re-victimisation loop that feeds the output of the final stage back into the first.

Each link in that chain runs its own economics. Typically operators who obtain initial access resell a compromised exchange account for between 50 and 500 US dollars depending on the value they can identify in it, while data brokers work either by subscription or by unit, with a complete KYC set priced anywhere from a few hundred to several thousand dollars. Exploitation operators take a significant margin on successful conversions, and cash-out operators generally charge between 8 and 25 percent of the volume they launder. Taken together, we assess this level of organisation as comparable in maturity to ransomware-as-a-service.

What makes France a strategic target rather than an incidental one?

Density combined with data quality. Approximately 11 percent of the French population held crypto-assets at the start of 2026, and the country concentrates several structural players in the European market, spanning hardware wallets, exchange and brokerage platforms, tax and accounting services, and retail savings applications.

What raises the value of that concentration is the nature of the records those players generate, which include verified identities from KYC processes, tax reports, aggregated balances and full transaction histories.

Where in the sector is the targeting actually concentrated?

Across twelve months of monitoring the principal underground forums and several private Telegram channels specialising in crypto-asset targeting, French references break down as follows.

Target categoryShare of mentions
Centralised exchanges38%
Hardware and software wallets21%
Tax and accounting services14%
French authorised providers and brokers11%
DeFi and bridges8%
Communities and influencers5%
Custody and asset management3%

Source: CybelAngel monitoring of forums and Telegram channels. Filtered set, observation floor.

Centralised exchanges and wallets concentrate the bulk of targeting, which is broadly what most security teams would predict. The finding that tends to surprise them is tax and accounting services sitting in third place, ahead of authorised providers and brokers.

Where does the data behind crypto fraud in France come from?

Three distinct vectors feed a single acquisition chain, and their value lies in how easily they combine.

Infostealers remain the dominant vector for individual compromise!

 Our continuous monitoring covers tens of millions of infected machines worldwide, a significant share of which carry credentials linked to crypto-asset platforms, and France ranks among the most represented countries on the perimeter targeting crypto-asset services. Malware-as-a-service models place these tools within reach of operators who hold no advanced technical skill of their own, and the exfiltrated logs typically contain credentials saved in browsers, session cookies that frequently allow two-factor authentication to be bypassed, and the local files of desktop wallets such as MetaMask, Phantom and Exodus. Torg Grabber, whose first samples date from December 2025, targets 728 browser extensions linked to wallets alongside 103 password management and two-factor authentication extensions.

Compromised provider databases supply something the individual logs cannot.

 They deliver a homogeneous population already qualified as crypto-holding, with contextual data that can be reused directly during exploitation. The compromise of Waltio, publicly confirmed in January 2026 and reported to concern around 50,000 users, exposed email addresses together with 2024 tax reports covering gains, losses and aggregated balances.

Broad-scope breaches circulate the same class of material at far greater scale. El DGFiP compromise, confirmed on 14 August 2026 for 678,000 individuals and professionals, put identity, address and reference tax income into circulation, all of which can be used to select wealth profiles before targeting them.

Across the first quarter of 2026 we also observed a sustained volume of French crypto database offers on the main criminal forums and Telegram channels, presented as originating from various providers and following a consistent commercial format in which a sample is published openly and the complete database is sold by lot. These listings find buyers quickly.

Why does the combination matter more than the volume?

Because a file that associates a verified identity, a means of contact and an order of magnitude of wealth allows an operator to sort targets before making first contact, which is the product the market is actually paying for. Raw volume without that combination is worth considerably less.

Alongside the large breaches, a specific market has organised itself around KYC data, meaning identity documents, proof of address and verification selfies, and these packs support complete identity theft including the opening of bank accounts in a victim’s name, SIM swap requests to mobile operators, and the creation of mule accounts on regulated platforms. One category is particularly prized, which is the list of people already defrauded, valued for its high conversion rate in recovery scam schemes and frequently sold with enriched fields covering the amount lost, the platform originally used and the date of the first fraud.

What does exploitation look like in practice?

Account takeover remains the scenario we observe most frequently wherever operators hold fresh credentials, and the sequence has become standardised. It runs from compromise of the main email address through stolen credentials or exfiltrated session cookies, to a reset procedure triggered on the exchange, the interception of validation codes, the modification of authorised withdrawal addresses, and finally a rapid drain into stablecoins. Session cookies are especially prized because they grant access without triggering the second factor, and the recent logs traded on forums almost systematically include the cookies that were active at the moment of exfiltration.

Fake support and fake adviser scenarios rest entirely on the contextual data acquired earlier, with credibility built on authentic personal details such as an exact account balance, a recent transaction or a reference to a support ticket. Recovery scams then close the loop, and the scale is documented: the FBI recorded more than 10,500 complaints in the United States in 2025 for roughly 1.4 billion dollars in declared losses, a category that includes the impersonation of law firms, public officials and the IC3 itself. In France the same phenomenon is documented at length by the AMF and the Paris public prosecutor.

What did analysing a live crypto phishing kit reveal?

Our Cyber Ops and REACT teams analysed fake support campaigns targeting crypto-asset platforms between February and August 2026. Four findings hold across the full set of pages examined.

FindingWhat we observedWhy it matters
Templates are reusedA single template appears across dozens of domains and, in several cases, across multiple brandsPoints to resource sharing between operators rather than the work of one actor
Three naming conventions coexistccTLD abuse producing a string that reads as the legitimate domain; brand combined with a support keyword; generic support or diagnostic domains carrying no brand string at allThe third family is well represented and escapes brand-keyword monitoring by construction
Domains are short-lived and proxiedMost are visible only within a window of one to three days, behind a reverse proxy provider that masks the real hosting and supplies the TLS certificateThe browser padlock carries no signal, reporting to the apparent host alone produces no takedown, and the template outlives its domains
The pretext is an incident, not a loginJourneys aim at durable access such as a recovery phrase or remote controlControls built around a username and password pair do not cover the actual objective

Case study: a remotely driven fake support kit

One deployment illustrates how far the engineering goes. A domain active in August 2026, built on the lexical field of fund recovery and impersonating the Bitpanda brand, served a page reproducing the Coinbase help centre, and the deception lay in the journey rather than in the appearance.

How the deception worked

  • The displayed address is permanently rewritten back to the root of the domain.
  • An operator drives the sequence of screens presented to the victim remotely.
  • Entries are transmitted keystroke by keystroke, which renders SMS, TOTP and email codes usable inside their validity window.

How the page qualified its target  in session

  • Order of magnitude of the account balance.
  • Date of last activity.
  • Wallet extensions detected in the browser.
  • Entry of a case number on opening, which places the page after a first contact rather than at the start of one.

How the page evaded inspection

  • Each visitor is scored across roughly fifteen automation signals, including mouse movements, with the score transmitted to the operator.
  • The page erases itself and redirects if browser developer tools are opened, so a scanner and a victim do not necessarily see the same thing.

What the code was built to collect

ModuleWhat it capturesWhat it tells us
Coinbase (the visible shell)Credentials, validation codes, and access to remote control softwareThe layer the victim believes they are interacting with
LedgerA recovery phrase and a passphraseNo exchange journey ever requires these, which clarifies the objective
GoogleThe mailboxThe first link in the account takeover sequence described above
Robinhood and BitpandaAdditional modules embedded in the same codeThe kit is built to work across several brands, not one

The brands named here are impersonated; however, they are not compromised.

The same package in a separate infrastructure

This deployment is not isolated. We found the same template running on a distinct cluster with the following characteristics.

  • 30 domains observed between 26 May and 20 August 2026.
  • Naming pattern of six digits followed by the brand name.
  • Cadence of one to two new domains per week.
  • Lifespan of one to three days per domain.

Those domains serve the same reproduction of the Coinbase help centre rather than a merely similar appearance, because the interface files carry identical fingerprints, which rules out two independent clonings. The infrastructure itself, however, is entirely distinct from the earlier case. The interface package is therefore shared between different operators, which is consistent with the phishing-as-a-service offers observed on underground forums, where kits, control panels and distribution are commercialised separately.

These observations concern pages and their code rather than identified victims, and the number of deployments we counted constitutes an observation floor.

How does the end of the MiCA transition change the threat?

It supplies attackers with a ready-made pretext. Since 1 July 2026, only authorised providers may deliver crypto-asset services in France, and several players have notified their customers that they are ceasing service, which alters the conditions under which a fake support approach is credible. An unsolicited message that is dated, carries a short deadline and invites the recipient to transfer holdings to another provider now arrives inside a sequence the recipient is already expecting.

Who is most exposed, and to what?

Target selection follows whatever material the acquisition phase has made available, and the result is a gradient rather than a set of discrete categories. Ordinary holders feed the volume scenarios of fake support and account takeover, where profitability rests on the number of attempts rather than the quality of any single one, while profiles whose file reveals significant wealth justify individual preparatory work. At the far end of that gradient, a limited but significant group concentrates the high-impact scenarios.

Founders, executives and influential investors in the sector are subject to specific pre-targeting on forums and Telegram channels, combining wealth data, addresses, habits and fragments of digital identity, and beyond conventional fraud these profiles are exposed to targeted extortion, threats against family members and physical coercion extending as far as abduction. Chainalysis records 30 publicly documented cases in France through mid-2026, against 19 across the whole of 2025, while the Ministry of the Interior, which counts recorded offences rather than publicly documented cases alone, reported on 30 June 2026 more than 70 acts of unlawful detention, abduction, extortion or attempted extortion linked to crypto-assets since January 2026, against 45 for all of 2025, alongside approximately 200 arrests. The operational markers recur consistently, and they include the targeting of relatives rather than the primary subject, the fake delivery driver, and teams of three to five individuals aged 17 to 25 recruited on social media for a few hundred euros.

For exposed organisations, executive security has therefore become a mixed subject, combining a cyber dimension that covers reduction of public exposure, management of digital identities and monitoring of breaches affecting the immediate circle, and what’s more, a governance dimension.

What should French platforms and providers take away from this report?

Here are five priorities we recommend meaning exchange platforms, wallet publishers, aggregators, tax and accounting services and connected providers.

  1. Monitor exposed credentials continuously and reset on detection. This covers both staff and customers appearing in infostealer logs, and the useful window is measured in hours rather than days.
  2. Monitor customer database exposure across forums, Telegram channels and criminal marketplaces.
  3. Require re-authentication before any withdrawal to a new address, and invalidate open sessions as soon as a credential or a factor changes.
  4. Establish an extortion runbook for exposed executives, covering conduct in the face of a direct cyber or physical threat, the contacts to reach, and a family alert protocol.
  5. Impose multi-signature, a waiting period and a four-eyes principle on significant transfers, so that an executive under duress cannot transfer alone.

Beyond those five, a second tier of measures reinforces the same objectives: a non-circumventable cooling-off period following any change of withdrawal address, email, telephone or MFA, with no exception routed through support; FIDO2 generalised across sensitive access including internal systems, with SMS removed from recovery factors; a published verification procedure for inbound contacts, backed by an anti-phishing code on customer emails so that the code covers email while the published procedure covers the telephone; sector-specific social engineering training prioritising staff with access to critical systems, customer databases or support functions; monitoring of brand impersonation across clone sites, fraudulent accounts and fraudulent mobile applications; and extension of breach monitoring to the immediate circle around executives.

What should individual holders take away?

Three measures come first, with a higher bar applying to publicly exposed profiles. Segment your holdings so that any significant reserve sits in cold storage on a dedicated hardware device while only current activity remains in a hot wallet. You should also adopt strong authentication that does not depend on SMS, using either a FIDO2 hardware key or a TOTP application, both of which protect against SIM swap. And make sure to verify any transfer instruction connected to a change of provider against the AMF whitelist or the ESMA register before initiating the transfer from the official application rather than from the link you received, because a provider has no need to send you a destination address by email.

A second tier reduces your presence in the files described above. So use dedicated credentials that are distinct per platform and unconnected to your real identity, expose nothing publicly in terms of holdings, gains, invested amounts or wallet screenshots, and keep your real identity separate from any pseudonyms. You should expressly verify every solicitation through the platform’s official site rather than a link received by email or message, bearing in mind that urgency is a near-systematic marker of fraud. And give no follow-up whatsoever to an offer to recover funds after a first fraud, reporting it instead to the AMF and to Pharos.

CTA button here: ACCESS THE FULL NOTE

Contact us to access the full threat note. Please note this report is available in French.

Sobre el autor