Digital Rent Scam: Hackers Exploit Tenants with Payment Redirection Fraud

Digital Rent Scam: Hackers Exploit Tenants with Payment Redirection Fraud

Covert Rent Fraud Campaign Exploits Tenant Trust in French-Speaking Regions

An emerging cyber threat is preying on tenants in French-speaking regions, leveraging carefully crafted deception to reroute rental payments into fraudulent bank accounts. This advanced rent payment scam, orchestrated by a threat group tracked as TA2900, operates under the guise of legitimate property management communication.

The scheme is predominantly aimed at individuals in France and parts of Canada, exploiting the fear of financial penalties or eviction to prompt swift, unquestioning compliance. Victims are presented with convincing messages claiming that rent payments have failed and urging immediate action to transfer funds to a newly provided bank account.

These fraudulent notices mimic official correspondence, complete with familiar industry terms and polished branding—such as the use of “Relevé d’Identité Bancaire” (RIB)—to disarm skepticism. Attackers deploy this tactic repeatedly, with each bank account typically used for only a few campaigns before being replaced, suggesting a disciplined and adaptive operation.

TA2900’s infrastructure shows signs of careful planning. Campaigns often originate from compromised email addresses linked to educational institutions, increasing the perceived legitimacy of the requests and helping evade basic security checks. Messages usually carry neutral subject lines like “Loyer” or “Nouveau RIB” and are accompanied by PDF attachments that mimic property management forms, complete with logos and jargon that mirror actual French rental processes.

What sets this operation apart is the psychological precision behind its social engineering. By implying that the tenant’s housing situation is in jeopardy, attackers manufacture urgency that overrides the instinct to double-check details. The messaging is not only linguistically accurate but also contextually intelligent—incorporating terminology like “Garantie des loyers” and “Gestion immobilier comptabilité” to appear fully authentic.

Researchers at Proofpoint have traced over 50 coordinated phishing campaigns, each meticulously crafted and adapted over time. This continuous evolution and the strategic use of compromised infrastructures underscore the need for vigilant digital hygiene among renters and landlords alike.

Screenshot

TA2900 Fraud Campaigns: Manipulative Messaging and Trusted Banking Channels Fuel Deception

According to intelligence from Proofpoint, threat actor TA2900 employs meticulously designed messages that feature banking credentials—such as IBAN and BIC codes—to give their scams an air of authenticity. Victims are often urged to respond with confirmation of payment or to pre-approve recurring transfers, a tactic that opens the door to repeated unauthorized withdrawals.

What makes this campaign particularly dangerous is its use of legitimate French financial institutions. Rather than spoofed or offshore banks, the attackers exploit accounts at actual “low-fee subsidiaries” of well-established banks. This strategy allows fraudulent transactions to blend seamlessly into the financial routines of unsuspecting victims.

Though TA2900’s physical location remains unidentified, analysts at Proofpoint believe with strong confidence that the operation is purely profit-driven, with no ideological or state-sponsored motive. Interestingly, despite the campaigns being conducted in French, linguistic anomalies suggest the use of machine translation tools, hinting that the perpetrators may not be native French speakers and could be operating from outside France or Canada.

This international dimension, coupled with the use of real banking infrastructure and emotionally manipulative messaging, makes TA2900’s campaigns particularly challenging to detect and disrupt.

More Articles & Posts