---
title: "Free Mobile and Free subscriber data incident"
description: "Evidence-backed account of Free Mobile and Free subscriber data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/free-mobile-free-subscriber-data-incident-2024"
markdown_url: "https://www.ally.security/incidents/free-mobile-free-subscriber-data-incident-2024.md"
stix_url: "https://www.ally.security/incidents/free-mobile-free-subscriber-data-incident-2024/stix.json"
---

# Free Mobile and Free subscriber data incident

An attacker infiltrated the companies' information systems and accessed subscriber-related personal data in October 2024. Access to personal data associated with approximately 24 million subscriber contracts, including IBANs for people who were customers of both operators.

Last modified Aug 9, 2026 · 1 source

## Summary

- **Environment:** Mobile operator whose subscriber data and information system were affected.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An attacker infiltrated [Free Mobile](https://mobile.free.fr/) and [Free](https://www.free.fr/) information systems and accessed subscriber-related personal data in October 2024. [1](#source-1)

## Impact

Access to personal data associated with approximately 24 million subscriber contracts, including IBANs for people who were customers of both operators. [1](#source-1)

Documented data types include:

- Financial account information — IBANs for convergent customers who subscribed to both Free Mobile and Free; not asserted for all contracts. [1](#source-1)
- Subscriber contract information — Subscriber-contract records; the CNIL summary does not enumerate every field. [1](#source-1)

A cited record reports 24,000,000 records (Approximately 24 million subscriber contracts, not 24 million verified unique people). [1](#source-1)

The CNIL found the companies' initial email notice omitted information people needed to understand consequences and protective steps. [1](#source-1)

## Timeline

### January 13, 2026 — Documented event

Date the CNIL says it issued the sanction decision. [1](#source-1)

### January 13, 2026 — Documented event

Date the CNIL says it issued the sanction decision. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The CNIL says an attacker infiltrated the companies' information systems and accessed subscriber personal data in October 2024; the summary does not provide a day-level incident date. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The CNIL ordered Free Mobile to complete sorting and purging unjustifiably retained former-subscriber data within six months of notification. The CNIL found that authentication for the companies' employee VPNs was insufficiently robust and their abnormal-behavior detection measures were ineffective. The CNIL imposed a €27 million administrative fine on Free Mobile. The CNIL imposed a €15 million administrative fine on Free. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/free-mobile-free-subscriber-data-incident-2024/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Violation de données : sanction de 42 millions d’euros à l’encontre des sociétés FREE MOBILE et FREE

regulatory · Commission nationale de l'informatique et des libertés · Jan 14, 2026

<https://cnil.fr/fr/sanction-free-2026>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   CNIL proceeding SAN-2026-001 against Free Mobile: Free Mobile
2. **Exposed Record Count · 100% confidence · current**  
   Free subscriber-contract data exposure: 24,000,000 record
3. **Resulted In · 100% confidence · current**  
   CNIL proceeding SAN-2026-001 against Free Mobile: The CNIL ordered Free Mobile to complete sorting and purging unjustifiably retained former-subscriber data within six months of notification.
4. **Resulted In · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: Free subscriber-contract data exposure
5. **Resulted In · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: The CNIL found that authentication for the companies' employee VPNs was insufficiently robust and their abnormal-behavior detection measures were ineffective.
6. **Affected Organization · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: Free Mobile
7. **Resulted In · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: The CNIL says an attacker infiltrated the companies' information systems and accessed subscriber personal data in October 2024; the summary does not provide a day-level incident date.
8. **Resulted In · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: The CNIL found the companies' initial email notice omitted information people needed to understand consequences and protective steps.
9. **Resulted In · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: CNIL proceeding SAN-2026-002 against Free
10. **Exposed Data Category · 100% confidence · current**  
   Free subscriber-contract data exposure: Financial account information
11. **Resulted In · 100% confidence · current**  
   CNIL proceeding SAN-2026-001 against Free Mobile: The CNIL imposed a €27 million administrative fine on Free Mobile.
12. **Occurred At · 100% confidence · current**  
   CNIL proceeding SAN-2026-001 against Free Mobile: 2026-01-13
13. **Exposed Data Category · 100% confidence · current**  
   Free subscriber-contract data exposure: Subscriber contract information
14. **Occurred At · 100% confidence · current**  
   CNIL proceeding SAN-2026-002 against Free: 2026-01-13
15. **Affected Organization · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: Free
16. **Affected Organization · 100% confidence · current**  
   CNIL proceeding SAN-2026-002 against Free: Free
17. **Resulted In · 100% confidence · current**  
   CNIL proceeding SAN-2026-002 against Free: The CNIL imposed a €15 million administrative fine on Free.
18. **Resulted In · 100% confidence · current**  
   October 2024 Free Mobile and Free intrusion: CNIL proceeding SAN-2026-001 against Free Mobile

</details>
