Published on 10 August 2026
A €42 million fine, 24 million compromised customer records and more than 5 million exposed bank details (IBANs) – that is the toll of a data breach now costing the French telecommunications group Iliad, with its Free and Free Mobile brands, dearly. On 13 January 2026, the French data protection authority CNIL imposed the highest GDPR fine of the year so far. The case is not merely a French affair: it offers German SMEs and website operators an unmistakable lesson in which security failings the supervisory authorities are now consistently punishing.
Between late September and late October 2024 – specifically in the period from 28 September to 22 October – an attacker penetrated the internal infrastructure of Free and Free Mobile. The point of entry was the company's VPN system (a VPN allows employees encrypted remote access to internal systems, for example when working from home). Via this VPN, the attacker reached an internal subscriber management tool and exfiltrated – that is, stole – records relating to 24 million customer contracts.
The affected data included, among other things, first name, surname, email address, postal address, date and place of birth, phone numbers, subscriber ID and contract data. Particularly sensitive: for around 5.11 million Freebox subscribers, the IBAN (the international bank account number) was also exposed. According to the company, passwords, bank card data and communication content such as emails, text messages or voicemails were not affected. This was not a ransomware attack involving encryption, but a targeted data theft.
The attacker, operating under the pseudonym "drussellx" on the hacker forum BreachForums, subsequently offered the data at auction for 175,000 US dollars. Another actor going by "YuroSh" later contacted the media and claimed to have carried out the actual infiltration with hacktivist motives. A suspect was arrested in France in November 2024. Free discovered the attack on 25 October 2024, immediately informed the CNIL and the cybersecurity agency ANSSI, and confirmed the incident publicly one day later.
In its investigation, the CNIL identified three separate GDPR violations. This threefold breakdown is the truly instructive core of the case.
Employees' remote access was not adequately secured. There was no robust multi-factor authentication (MFA) – that is, a second proof of identity in addition to the password, such as a one-time code via an app or a hardware token. A password alone was enough to log in to the VPN. In addition, the systems for detecting anomalous network behaviour were ineffective, allowing the attacker to operate undetected for several weeks. The CNIL put it plainly:
"The authentication procedure for connecting to the VPNs of Free Mobile and Free – used in particular for employees working from home – was not sufficiently robust. Moreover, the measures deployed by Free Mobile and Free to detect anomalous behaviour on their information systems were ineffective." – CNIL
Free did inform its customers about the incident by email – but this notification was incomplete. Under Art. 34(2) GDPR, data subjects must be able to understand the possible consequences of a data breach and the protective measures available to them. That is precisely what the email failed to deliver. The CNIL:
"The email sent did not contain all the necessary information from paragraph 2 of Article 34 of the GDPR […]; these omissions did not allow the data subjects to directly understand the consequences of the breach, nor the measures they could take to protect themselves." – CNIL
Free Mobile had stored the data of millions of former subscribers without a legal basis, well beyond the required period. There were simply no mechanisms to sort out and delete old data after the retention period had expired. This considerably increased the damage – every superfluous record was an additional one that could be stolen. Information governance experts at Kahn Consulting sum it up:
"Retaining old customer data 'just in case' is no longer a neutral business decision – it is increasingly treated as a security and compliance amplifier when something goes wrong. Every additional year is a bet you are going to lose." – Kahn Consulting Inc.
The CNIL ordered the new security measures to be completed within three months and the excess legacy data to be deleted within six months. The parent company Iliad has announced it will appeal before the Conseil d'État, France's highest administrative court.
Directly affected are exclusively customers of Free (internet/Freebox) and Free Mobile (mobile telephony) in France – both current and former. German SME systems are not directly affected by this specific incident. However, if you or your relatives have or had such a French subscription, you should take action. The Free Mobile data breach was added to the Have I Been Pwned database on 27 May 2025.
Even if you are not a Free customer: the real value of this case lies in the lessons for your own IT security. Security researchers and supervisory authorities agree – weak authentication on remote access is no longer a trivial offence today. The analysis service Kiteworks sums it up: "2FA is no longer a best practice, it's a requirement." Here are the concrete steps:
The Free case does not stand alone. Back in December 2022, the CNIL had already fined Free €300,000 – at the time partly because passwords were stored in plain text. That makes Free a repeat offender. And in June 2025, the German Federal Commissioner for Data Protection (BfDI) imposed a fine of €45 million on Vodafone, of which €30 million was for inadequate authentication processes alone.
The common thread is unmistakable: supervisory authorities are no longer sanctioning only the data protection violation itself, but the structural security gaps that made it possible in the first place. On the occasion of the Vodafone fine, BfDI President Prof. Dr Louisa Specht-Riemenschneider issued a remarkable appeal:
"Data protection is often mistakenly seen as an obstacle to IT investment. In fact, the opposite is true: without IT investment, security incidents – and sanctions from the data protection supervisory authority – are looming. Hence my call: invest rather than risk!" – BfDI
The figures underscore the trend. Fines for inadequate technical and organisational measures (Art. 32 GDPR) rose by more than 40 percent across Europe in 2025 (from 69 to 97 cases). In Germany, a total of 10,259 data breaches were reported in 2025 – a marked increase over 8,623 the previous year. Cumulatively, GDPR fines since 2018 add up to more than €7.1 billion.
Direct risk from this incident: low. German SMEs are not affected by the specific Free data breach.
Indirect regulatory risk: high. The case sets a clear precedent. Anyone still operating VPN access or website admin areas without MFA, with no defined retention periods for customer data, or without a response plan for data breaches, is taking on a substantial fine risk in the event of a breach or a regulatory audit – regardless of company size. Companies with large customer databases are especially in the spotlight: e-commerce shops, newsletter marketing, online booking systems.
Zlatko Delev of GDPRLocal recommends three simple check questions for every organisation:
"For any organisation reviewing its own attack surface, the fines point to the same starting questions: is multi-factor authentication actually enforced for remote access and sensitive systems? Is there a working process for objections to processing? And has every dataset described as 'anonymised' actually been tested against that standard – and not merely described as such in a policy document?" – Zlatko Delev, GDPRLocal
For the Iliad group, with annual revenue of more than €10 billion, €42 million is admittedly "only" around 0.42 percent of turnover – for an SME, a comparable ratio would be existentially threatening. But the real message of the case is not the absolute sum, it is the pattern: the CNIL punished three everyday failings at once that many companies will recognise – missing MFA, incomplete notification and undeleted legacy data.
The good news: all three gaps can be closed with manageable effort. Introduce MFA for your remote access, define retention periods and automate their implementation, and keep a response plan ready. These measures cost a fraction of what a fine – or the reputational damage following a data breach – would cost you. Or, in the words of the BfDI: invest rather than risk.