In September 2026, the Cash Investigation program on France 2 aired a report titled "Cyber Scams: Are the State and Companies Really Protecting Us?" The episode revisited a major data breach that occurred in October 2024 involving the French telecommunications company Free. The breach was traced back to an attacker who gained access to Free's internal systems through a virtual private network (VPN) used by remote workers. The hacker then impersonated the IT department to trick other employees into granting further access, remaining undetected for several weeks. During this time, the attacker extracted data from 24 million contracts, including names, postal addresses, contact details, and IBANs (International Bank Account Numbers) for some individuals. Following the breach, the hacker allegedly sold the stolen data, prompting an investigation by the CNIL, France’s data protection authority.
The CNIL's investigation found that Free had failed to implement proper measures to detect unusual activity, which contributed to the breach. The authority's rapporteur criticized the company for not adequately securing customer data and for not informing affected customers about the risks posed by the leak. In response, Free's legal representative attempted to minimize the severity of the breach, stating that only IBANs were considered sensitive data, while other details like names and addresses were not. However, this claim was challenged, as such data can be used by cybercriminals to craft more convincing phishing attacks and fraudulent messages.
On January 13, 2026, the CNIL imposed a fine of 42 million euros on Free, with 27 million euros allocated to Free Mobile and 15 million to the main Free company. The company has since appealed the decision to the Council of State, France's highest administrative court. In addition to the inadequate detection of the breach, the CNIL also criticized Free for retaining sensitive data, such as IBANs and other information from former customers, for far longer than necessary. This excessive data retention not only increased the number of potential victims but also played a role in determining the size of the fine.
Free Faces 42 Million Euro Fine Over Data Leak and Security Failures
AI-rewritten from original reportingHow it works
data-breachfreecybersecuritycnilfrauddata-protection



