Free , the second largest Internet service provider (ISP) in France , announced a breach of customer data after hackers broke into its systems.

The company, which says it had over 22.9 million mobile and fixed-line subscribers at the end of June, is a subsidiary of Iliad Group, the sixth-largest mobile operator in Europe (based on subscribers).
Free says it has notified the relevant authorities about the cyberattack and the breach of customer data.
See also: Landmark Admin says data breach affects 800,000 people
“Affected subscribers have been notified or will be notified shortly via email,” a Free spokesperson told BleepingComputer, adding that “no operational impact on our activities and services has been observed.” Furthermore, the French ISP said that all necessary measures were taken to terminate the attack and strengthen the protection of systems.
According to Free, the attack targeted a management tool that exposed subscriber data. However, the attackers were unable to access customer passwords, bank card information, and communication content (including emails, SMS, voicemails, etc.).
The stolen data is now being auctioned off on BreachForums, with the threat actor – known as “drussellx” – claiming that the data affects almost a third of France’s population.
“The data breach affects 19.2 million customers and contains over 5.11 million IBAN numbers. It affects all Free Mobile and Freebox customers and includes the IBANs of all 5.11 million Freebox subscribers,” the attacker says.
See also: Henry Schein reveals data breach
A sample of some of the allegedly stolen data was also published, as proof that the data being auctioned is legitimate.

Additionally, the attacker said he may let potential customers search the stolen database to ensure that “all of the database recovered” is for sale.
Regarding the stolen IBANs, Free says that able to steal IBANs only from a few landline subscribers and that these are not enough to cause an immediate problem.
“If subscribers, however, notice an unusual direct debit, their bank is obligated to compensate them. They have 13 months to report the fraudulent direct debit,” Free said.
The company also told customers to be wary of potential phishing attempts. “Never share your passwords or bank card via email, SMS or during a call.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Change Healthcare data breach affected 100 million people
In today’s digital age, data breaches have become a common occurrence and it is vital for companies to measures cybersecurity. This Free incident serves as a wake-up call for businesses of all sizes to invest in strong security to protect their customers’ sensitive information. Cybercriminals are evolving, and without proper defenses, any organization can fall victim to such attacks.
Source: www.bleepingcomputer.com
