The French data protection authority CNIL has imposed a total of 42 million euros in fines on Free Mobile and its parent company Free, sending a clear message to the telecommunications industry: poor data protection will not be tolerated. The case concerns a serious data breach that occurred in October 2024 and affected tens of millions of subscribers.

Free is the second largest internet service in France, which makes the incident particularly critical in terms of both consumer trust and national digital security.
See also: Betterment: Hackers gained access to internal systems
The cyberattack that exposed 23 million subscribers
According to the investigation, hackers managed to gain access to the company's internal management tool, extracting sensitive information from mobile and landline. The breach led to the leakage of data of almost 23 million users.
The stolen data appeared for sale on a dark web forum by an account with the alias “drussellx.” The perpetrator claimed that the attack affected 19.2 million people, with around 25% of the records allegedly containing bank details such as IBANs — a particularly worrying finding with serious implications for the financial security of the victims.

Free's mistakes and GDPR violations
Although Free stepped up its cybersecurity measures following the incident, the CNIL found that the previous negligence constituted a clear violation of the General Data Protection Regulation (GDPR). The investigation was launched following more than 2,500 complaints from directly affected citizens.
See also: Monroe University: 2024 data breach affects 320,000 people
The French authority identified three main areas of infringement. First, insufficient technical and organisational security measures, such as weak VPN authentication for remote employee access and an incomplete mechanism for detecting suspicious activity. Second, insufficient information to users, as notification emails did not clearly explain the risks or provide practical protection instructions. Third, excessive retention of personal data of former subscribers, beyond the time limit justified by accounting or legal obligations.
Mandatory measures and tight deadlines
The CNIL did not limit itself to imposing fines. It ordered Free and Free Mobile to fully implement the new security measures within three months, while Free Mobile must proceed with the classification and deletion of unnecessary customer data within six months.
The case highlights how critical the principle of data minimization is, one of the most often neglected requirements of the GDPR by large organizations.
See also: AZ Monica Hospital: Servers offline due to cyberattack

Escalation of incidents in French telecommunications
The Free incident is not an isolated incident. Following the attack, France has been hit by a wave of cyber incidents in the telecommunications sector. In July 2025, Orange France announced a breach that caused operational disruptions to its systems. A month later, Bouygues Telecom revealed a data breach involving 6.4 million customers.
The accumulation of these incidents reinforces concerns about the resilience of critical digital infrastructures and confirms that cybersecurity is no longer a technical issue, but a key pillar of corporate responsibility and public trust.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
