Update (Feb. 9): Fairphone has responded to data breach fears, noting that a “malfunction” on the part of its email partner, Bloomreach, is likely the cause, and that investigations are still ongoing.

Some users are also sharing statements from Fairphone support that say the issue has now been fully resolved. Here’s a screenshot of one such statement:

Original article follows:
When the Fairphone 6 arrived last year, iFixit didn’t mince words in their praise for the sustainable brand. They summed up the company’s ethos with a powerful line: “If you don’t want your data sold, Fairphone 6 should be your next phone.” It was a strong endorsement for a company that prides itself on privacy and longevity. However, for a section of users, that promise of data security is feeling a bit shaky.
A highly sophisticated scam email has begun hitting some Fairphone customers, triggering concerns that the company’s store data may have been compromised.
The issue first came to light this week on the Fairphone community forum. User Nicoolas reported receiving an order confirmation email that was a replica of a genuine purchase they made a year ago, on January 17, 2025.
The email contained accurate details, including the correct Order Number, billing address, and shipping information. However, there were red flags. The email was sent from [email protected] rather than the official [email protected] address. The links within the email, originally pointing to the Fairphone store, had now been replaced with suspicious URLs hosted on cdn.eu1.exponea.com.
You can see a screenshot of the email below (in French):

The text translates to: “Thank you for your order… You will find the details of your order below. If you wish to check the status of your order, please log in to your account.”
This doesn’t appear to be an isolated incident. Shortly after the initial post, other users chimed in with identical experiences. User jdanielp noted that their mother received a duplicate confirmation for a Fairphone 4 order placed in Autumn 2024. Another user, G_G, reported receiving a confirmation for a two-year-old order containing similar malware links.
The reports aren’t limited to the official forum. On Mastodon, a German user shared a similar warning: “I just got a fake e-mail supposedly from Fairphone. My order confirmation from 2 years ago was provided with malware links.”

What makes this phishing campaign particularly dangerous and convincing is the scammers’ access to valid historical data. Phishing emails are often generic, hoping to get a lucky hit. In this case, the attackers possess valid email addresses of Fairphone customers, exact dates of past orders, specific order IDs, and correct billing/shipping addresses.
If different people using different email providers have all received it, it’s probably that Fairphone’s store got hacked. But this is just speculation, and nothing has been confirmed yet.
As of this writing, reports are still trickling in. A scan of the Fairphone subreddit and X (formerly Twitter) shows no widespread mention of the issue yet, suggesting the campaign has just begun or is currently targeting a specific subset of users (potentially in Europe, given the French and German reports).
We have yet to see an official statement from Fairphone regarding a potential breach of their e-commerce platform.
If you receive an email from Fairphone confirming an order you didn’t place or re-confirming an old one, do not click any links. Check the sender address carefully, verify the URL by hovering over links (without clicking), and report the suspicious email to Fairphone support immediately.
We will update this article as more information becomes available.