An Intriguing Email Before the Trap

It all starts with a deliberately vague subject: “A sum is intended for you.” The wording piques curiosity without directly announcing a refund or demanding money. It creates anticipation and prompts the recipient to open the message to understand what it is about. Once opened, the email takes on the main graphic codes of the Health Insurance: logo, blue and white colors, reference to a personal space, and administrative presentation that gives it the appearance of institutional communication.

The text mentions a “sum attached to your file,” a “treatment,” and a “registered agreement.” The recipient is faced with a procedure presented as almost complete — there would just be one formal step left to complete. The button “Register my agreement” participates in this mechanism: it seems less suspect than an injunction like “Receive my refund.” The victim thinks they are confirming an administrative operation, not initiating a sensitive transaction.

The amount of €49.99 is carefully chosen: significant enough to attract attention while remaining compatible, in the recipient's mind, with an ordinary health refund. The reference “V.2026.0714” adds a layer of credibility by simulating an internal identifier.

What the Health Insurance Really Does

However, this presentation diverges from the official practices of the Health Insurance. When it genuinely informs an insured person of a payment, its email does not specify the amount or the reason for the payment and refers to the Ameli account. The subject used for this type of notification would be “Payment Information.” The presence of a specific sum in an email is thus a warning signal.

After the Click: An Infrastructure That Changes Face

It is after the click that the campaign reveals its true sophistication. The address used by the hackers can lead to Le Monde instead of displaying a page imitating Ameli. This variable behavior, depending on the time or IP address, is compatible with a technique called cloaking.

The principle of cloaking consists of selecting the content presented according to the visitor. A server can take into account:

  • the IP address, estimated country, ISP, ASN;
  • the browser, operating system, cookies, HTTP referer;
  • the parameters included in the link, number of visits, or time of day.

A victim matching the expected profile could thus receive the Ameli phishing, while an automatic scanner, an address from a data center, a foreign connection, or a known IP would be redirected to Le Monde.

Why Le Monde?

The chosen destination has operational significance. A 404 error or an empty page would immediately signal a malfunction. A redirect to Le Monde resembles a navigation anomaly: the victim may think that the operation has expired or that the link is malfunctioning. A researcher or a security tool, on the other hand, may never observe the fraudulent content.

This type of filtering by digital fingerprinting is not isolated. BleepingComputer and The Hacker News recently documented ClickFix campaigns using over 250 domains with fingerprinting to mask their malware lures, confirming that cloaking is a growing trend among cybercriminals in 2026.

A Fake Store as Covering Infrastructure

The domain used adds an additional dimension to the operation. The phishing occurs under a subdomain linked to a company presented as a food store located in Chandigarh, India. The site offers fruits, vegetables, rice, dairy products, and also features sections for investors, distributors, and recruitment.

According to ZATAZ's analysis, this digital presence is very recent. Job offers and franchise opportunities are being disseminated via an Instagram account created just a few days earlier. Texts, illustrations, and videos are generated by artificial intelligence.

Three hypotheses are possible:

  1. A facade created specifically to add depth to the infrastructure. A store, products, institutional pages, a social account, recruitments, and videos form a much more credible environment than a simple disposable domain. AI significantly reduces the effort required to create this backdrop.
  2. A compromised authentic site: the subdomain may have been created or hijacked without the involvement of the legitimate owner. A domain associated with a commercial activity often seems less suspicious than an address built around the words “ameli” or “refund.”
  3. A hybrid infrastructure, with a real commercial activity used simultaneously as cover.

The in-depth investigation by ZATAZ leans toward the first hypothesis: the entire infrastructure of this company appears to be false.

The Click Itself as a Goal: Data Collection

The most troubling point of this campaign is that the click can constitute the initial objective, well before any phishing page. A URL distributed by email can include a unique identifier. When a recipient opens the link, the server learns that the targeted address is likely active and that its user is responding to a topic related to the Health Insurance.

Beyond simple activity confirmation, the connection can reveal:

  • the time of the click and the public IP address;
  • an approximate location, ASN, ISP;
  • the browser, operating system, device type, and configured language;
  • several HTTP characteristics completing this profile.

A simple email address thus becomes a behavioral intelligence: an active user, receptive to a promise of reimbursement, connected from France, with an identifiable technical environment and a known time frame.

This qualification can be used to prepare a second, more credible operation. The attackers then have elements to adapt the pretext, timing of contact, or technical presentation. A subsequent campaign could take the form of a fake Health Insurance advisor, a bank, a mutual insurance company, a delivery service, or technical support.

A Concerning Context for French Users

This campaign is part of a particularly tense context for cybersecurity in France. A few days earlier, on August 8, 2026, ZATAZ revealed the discovery of a pirate storage gathering over 1.7 billion unique email/password pairs linked to the French domain, about 69% (1.18 billion entries) of which come from phishing campaigns conducted over thirteen years.

Moreover, the day before this discovery, on August 10, 2026, ZATAZ documented another sophisticated phishing campaign imitating the AR24 service (electronic registered letter), using a CAPTCHA to complicate automated analysis and collecting email credentials from six providers (Outlook, Yahoo, Orange, Bouygues Telecom, Free, and SFR) before redirecting the victim to the real AR24 site to delay detection.

These three cases illustrate a major evolution: phishing campaigns no longer just aim to steal credentials en masse. They filter, qualify, and prepare the ground for more targeted and credible attacks.

How to Protect Yourself

In the face of this type of threat, several reflexes are necessary:

  • Verify the subject and content: the Health Insurance never specifies the amount of a refund in an email. The official subject is “Payment Information.”
  • Check the domain displayed in the browser's address bar after a click. A subdomain linked to an Indian store has no relation to Ameli.
  • Never enter credentials following a click from an email. To access your Ameli account, you should type the official address yourself in the browser.
  • Enable multi-factor authentication on all accounts that offer it.
  • Use a password manager to avoid reusing passwords across services.
  • Report suspicious emails to the official platform Signal Phishing (signal-phishing.gouv.fr) or via the reporting button integrated into most messaging services.

The danger of this campaign does not lie solely in the page that appears after the click: the information obtained about the one clicking may already constitute a first step of the attack. Caution regarding any email promising an unexpected amount remains, as of August 2026, more relevant than ever.