Unexpected emails from Fairphone

Hi,

I ordered a Fairphone 3 battery one year ago, on January 17th 2025.

So far, so good, except I just received the exact same order confirmation email, but sent by noreply@test.email.bloomreach.com instead of noreply@tmail.fairphone.com and all URLs were replaced by scam looking ones https://cdn.eu1.exponea.com/production5/...

All the rest is identical, including order number, billing ans hipping information.

My conclusion is that either my email, email provider, Fairphone or some other third parties got hacked recently.

Anyone else received this ?

4 Likes

My mum received one replicating her order for a FP4 in Autumn 2024, which she had just emailed me about. Presumably Fairphone has suffered a data breach?

3 Likes

Just saw a third report of the same thing on Mastodon (in :germany: German). I took this as sufficient reason to post a warning on Mastodon.

Alerting @Fairphone_CM

7 Likes

Hi,

same thing happened to me today:

Order confirmation from about 2y ago, malware links, same sender as yours.

I reported it to Fairphone support.

2 Likes

Uh-oh. If different people using different email providers have all received it, it’s probably that Fairphone’s store got hacked. Let’s just hope the hackers didn’t get customers payment information… :worried:

3 Likes

I don’t think that this is a scam. They seem to use this service for their marketing mails - including all those fancy tracking links. exponea.com forwards to bloomreach.com which reads: “Marketing Automation That Personalizes Every Customer Moment” as their headline.
Most if not all Fairphone marketing mails go through this service. I just verified that for the last marketing mail I got titled “Make 2026 the year you made the fair choice.”

The use of test suggests to me that someone played around with configuration and accidentally published something that was not meant to be public. The links are tracking links as in all those marketing mails, but most likely won’t lead to any scam site.

(I don’t want to advocate for using such “marketing services” at all, but I think it’s important to distinguish this from a data breach.)

8 Likes

That sounds reassuring, thank you for investigating. Hopefully Fairphone will admit to this in due course.

You’re kidding, aren’t you

1 Like

Me, too. As all data in the mail was exactly as in my order 2 years ago, probably the Fairphone shop got hacked …

Dear community,

We’ve looked into the emails you’ve been getting since last evening.

At this point it is likely that these are coming from our official emailing tool, Bloomreach, triggered by an internal malfunction, and not from a data breach.

We’re investigating and will keep you posted.

Thanks for your patience,

The Fairphone Team

15 Likes

“Unexpected emails from Fairphone”

when i read that title, i thought for a moment that people had started getting replies from support.

reading many threads, THAT would certainly be ‘unexpected’.

but, no. :person_facepalming: sigh.

3 Likes

Problem solved:

7 Likes