Free Mobile and Free subscriber data incident

An attacker infiltrated the companies' information systems and accessed subscriber-related personal data in October 2024. Access to personal data associated with approximately 24 million subscriber contracts, including IBANs for people who were customers of both operators.

Last modified

Summary

  • Environment: Mobile operator whose subscriber data and information system were affected.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

An attacker infiltrated Free Mobile and Free information systems and accessed subscriber-related personal data in October 2024. [1]

Impact

Access to personal data associated with approximately 24 million subscriber contracts, including IBANs for people who were customers of both operators. [1]

Documented data types include:

  • Financial account information — IBANs for convergent customers who subscribed to both Free Mobile and Free; not asserted for all contracts. [1]
  • Subscriber contract information — Subscriber-contract records; the CNIL summary does not enumerate every field. [1]

A cited record reports 24,000,000 records (Approximately 24 million subscriber contracts, not 24 million verified unique people). [1]

The CNIL found the companies’ initial email notice omitted information people needed to understand consequences and protective steps. [1]

Timeline

  1. Documented event

    Date the CNIL says it issued the sanction decision.

    [1]
  2. Documented event

    Date the CNIL says it issued the sanction decision.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The CNIL says an attacker infiltrated the companies’ information systems and accessed subscriber personal data in October 2024; the summary does not provide a day-level incident date. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The CNIL ordered Free Mobile to complete sorting and purging unjustifiably retained former-subscriber data within six months of notification. The CNIL found that authentication for the companies’ employee VPNs was insufficiently robust and their abnormal-behavior detection measures were ineffective. The CNIL imposed a €27 million administrative fine on Free Mobile. The CNIL imposed a €15 million administrative fine on Free. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]