France’s data protection regulator CNIL issued a collective €42 million fine against Iliad Group subsidiaries Free and Free Mobile for GDPR violations tied to an October 2024 breach that exposed personal data for more than 24 million individuals, including sensitive financial identifiers such as IBANs. CNIL cited the scale and sensitivity of the compromised data, as well as the companies’ profits, in setting penalties of €27 million for Free and €15 million for Free Mobile.
Regulators said the intrusion was enabled by inadequate security controls, including a weak VPN authentication process and insufficient monitoring to detect anomalous activity. Reporting indicates the attacker accessed Free’s network via the corporate VPN, then reached Free Mobile’s subscriber management tool MOBO, which at the time allowed searches across both Free and Free Mobile customer datasets; exfiltration reportedly began in early October 2024 after initial access in late September. CNIL also faulted the companies for insufficient breach communications to impacted customers and for improper data retention (including retaining former subscribers’ data), while noting remediation steps have been initiated and further security improvements were ordered.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
As part of its enforcement action, CNIL ordered the companies to complete newly implemented security measures within three months and required Free Mobile to sort and delete excess retained customer data within six months. The regulator also noted the companies had already taken steps to improve security during the investigation.
On 2026-01-14, France's data protection regulator CNIL announced a combined €42 million fine against Free and Free Mobile for GDPR violations tied to the breach. CNIL cited insufficient security controls, inadequate breach notifications to affected individuals, and excessive retention of former subscribers' data.
Following the October 2024 breach, exfiltrated customer information was offered for sale on a hacker forum. CNIL later said it received more than 2,500 complaints related to the incident.
On 2024-10-21, the attacker informed the companies about the breach. By that point, data from more than 24 million individuals had been compromised in the incident.
Post-incident analysis found that exfiltration of customer records started on 2024-10-06. The stolen data ultimately involved records tied to about 24.6 million fixed and mobile contracts, including sensitive personal and financial identifiers such as IBANs.
The intrusion into Free and Free Mobile reportedly began on 2024-09-28, when attackers accessed Free's environment through the company VPN and used the MOBO subscriber management tool to reach customer data across both businesses. CNIL later concluded the access was enabled by weak VPN authentication and poor detection of abnormal activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.