42 Million Euro GDPR Fine: CNIL Penalizes Free After Data Breach

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Initial Access

The attacker breached the internal infrastructure via the insufficiently secured VPN used for employee remote access.

T1133 – External Remote Services T1078 – Valid Accounts
  • Entry point: VPN for home-office access of Free and Free Mobile
  • No robust multi-factor authentication (MFA) – a password alone was enough
  • Attack window: 28 September to 22 October 2024
  • Violation of Art. 32 GDPR (security of processing)
PHASE 2/5 · Defense Evasion

The attacker operated undetected for several weeks because the systems for detecting anomalous network behavior were ineffective.

T1562 – Impair Defenses
  • Anomaly detection measures deemed ineffective by CNIL
  • Undetected activity over roughly four weeks
  • Attack only discovered on 25 October 2024
PHASE 3/5 · Collection

Via the VPN, the attacker gained access to the internal subscriber management tool and collected millions of customer records.

T1213 – Data from Information Repositories
  • Access to internal subscriber management tool
  • Affected: name, email, address, date of birth, phone numbers, subscriber ID, contract data
  • 5.11 million Freebox IBANs exposed
  • Excessive retention of legacy data increased the scope (Art. 5(1)(e) GDPR)
PHASE 4/5 · Exfiltration

The attacker exfiltrated records covering 24 million customer contracts from the internal infrastructure.

T1041 – Exfiltration Over C2 Channel
  • 24 million compromised customer records
  • 'drussellx' claimed exfiltration of 19.2 million subscribers on 17 October 2024
  • No ransomware – targeted pure data theft
PHASE 5/5 · Impact

The stolen data was auctioned on a hacking forum, resulting in fines and fraud risk for millions of customers.

T1657 – Financial Theft
  • 'drussellx' offered the data for USD 175,000 on BreachForums
  • EUR 42 million CNIL fine (EUR 27M Free Mobile, EUR 15M Free)
  • IBAN leak enables risk of unauthorized SEPA direct debits
  • Added to Have I Been Pwned on 27 May 2025
Short & clear answers
Frequently asked questions about this incident
Am I affected by the Free data breach?
Only current and former customers of Free (internet/Freebox) and Free Mobile in France are directly affected. If you or your relatives have or had such a subscription, your name, address, date of birth, phone number and contract data may be affected – and for around 5.11 million Freebox subscribers, the IBAN as well. You can check your email address on haveibeenpwned.com, as the breach has been listed there since 27 May 2025.
What should I do now if I'm a Free customer?
Check your bank statements for unauthorized SEPA direct debits and request chargebacks if necessary, since IBANs were exposed. Be especially wary of phishing emails or calls referencing your Free contract details, as these can be convincingly personalized. If you experience misuse, you can file a criminal complaint and lodge a complaint with the CNIL.
What data was stolen in the attack?
Records for 24 million customer contracts were stolen, including name, first name, email address, postal address, date and place of birth, phone numbers, subscriber ID and contract data. For around 5.11 million Freebox subscribers, the IBAN was also exposed. According to the company, passwords, bank card data and communication content such as emails, SMS or voicemails were not affected.
Why was Free fined 42 million euros?
The CNIL identified three GDPR violations: insufficiently robust VPN authentication without effective multi-factor authentication (Art. 32), incomplete notification of those affected (Art. 34), and excessively long retention of former customers' data without a legal basis (Art. 5). The fine consists of 27 million euros against Free Mobile and 15 million euros against Free.
What should German SMEs learn from this case?
Secure all remote access points such as VPN, RDP and admin portals with multi-factor authentication – passwords alone are no longer sufficient according to the current state of the art. Enable centralized logging and anomaly detection to spot suspicious access early. Also define and automate deletion deadlines for old customer data, since every unnecessarily stored record increases the potential damage in an attack.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.