Free fined €42 million by the CNIL: what the October 2024 data breach changes for subscribers
The Texto SMS Gratuit team

The Texto SMS Gratuit team

25 July 2026 · 6 min read

On 8 January 2026, the CNIL's restricted formation handed down a landmark deliberation: €42 million in fines against Free Mobile (€27M) and Free (€15M) for the cyberattack they suffered between 28 September and 22 October 2024. Twenty-four million contracts exposed, IBANs out in the wild, and an operator that is still contesting the sanction before the Conseil d'État today. What really happened, and what does it change for you?

A massive cyberattack, kept silent for 24 days

It all started with a silent intrusion into Free Mobile's systems. For nearly 24 days, between 28 September and 22 October 2024, the attacker — a minor who was charged in January 2025 — was able to move around inside the databases. The irony: it was the attacker himself who alerted Free Mobile on 21 October 2024, forcing the operator to notify the CNIL two days later.

The toll, made public by deliberation SAN-2026-001, is staggering:

Type of contractNumber of accounts affected
Mobile contracts (Free Mobile)19,460,891
Fixed contracts (Free)5,172,577
Total24,633,469 contracts

The data stolen: identity, contact details, contractual information — and, for "convergent" customers (both Free Mobile and Free subscribers), the IBAN. Around 100,000 IBANs were released online and then exploited for bank-transfer scams and targeted phishing.

A computer screen showing a digital padlock and lines of code, illustrating cybersecurity and the protection of personal data.

Photo: Unsplash — cybersecurity is becoming a central issue for French telecom operators.

Three GDPR breaches sanctioned

The CNIL identified three distinct violations of the General Data Protection Regulation, each constituting an autonomous breach:

  1. Article 5(1)(e) — Excessive retention period (Free Mobile only). The operator kept the data of more than 15 million contracts terminated for over five years, including 2,806,690 contracts with no justification whatsoever. Some of this data was over ten years old. For the CNIL, this is clear-cut negligence: a telecom operator must know that this data has no further use once the contract is closed.

  2. Article 32 — Insufficient security measures. Authentication to the employees' VPN relied on neither multi-factor authentication (MFA) nor a machine certificate for remote endpoints. Anomaly detection was ineffective, and the passwords for the internal MOBO tool were stored insecurely. These very flaws enabled the initial intrusion.

  3. Article 34 — Too vague a communication to the data subjects. The e-mail sent to subscribers was deemed "too general and abstract" by the restricted formation: it failed to explicitly mention the risks of identity theft or fraudulent direct debits, nor the concrete remedial measures to be put in place. For the CNIL, a GDPR notification must be operational, not legalistic.

Free announced an appeal to the Conseil d'État, calling the decision a "severity without precedent and out of all proportion" to previous cyberattack cases. The file therefore remains open.

Why this sanction sets a precedent

The €42 million fine is one of the heaviest ever imposed by the CNIL on a telecom operator. It is based on the consolidated turnover of the Iliad group (€10.024 billion in 2024), in line with the notion of "undertaking" under competition law (CJEU, 5 December 2023, C-807/21).

More important than the amount is the method: the CNIL sanctioned three distinct breaches and ordered, under a penalty of €50,000 per day of delay, compliance with the following:

  • Six months to sort and purge the personal data of terminated contracts.
  • Three months to strengthen security measures (MFA, certificates, anomaly detection).

The decision is published on the CNIL's website and in the Journal officiel for two years — a reputational blow for the group. It is a signal sent to all operators: retention of terminated customers' data "by default" is no longer tolerated, and the security of a VPN can no longer rely on a mere username/password pair.

What subscribers must (and must not) do

If you are — or have been — a Free or Free Mobile customer, here is the immediate checklist to follow, which we also cover in our guide to protecting the privacy of your SMS:

  1. Monitor your bank statements. If your IBAN has leaked, fraudulent direct debits may appear months after the attack. Report any unknown transaction to your bank immediately.
  2. Beware of phishing by SMS and e-mail. Hackers now cross-reference data from multiple leaks. A message that knows your name, your operator and your IBAN becomes extremely credible. We detailed this in our article on smishing in France in 2026.
  3. Change the passwords of your sensitive accounts (bank, tax office, main e-mail), especially if you reuse the same password as on a Free account. Credential stuffing is the first use made of stolen credential databases.
  4. Do not pay any "unsubscribe ransom". No official procedure will ask you to pay to "remove" your data from a leak: that is a scam.
  5. Check Free's dedicated page and, in case of doubt, file a complaint on the Ministry of the Interior's THESEE platform or with the CNIL.

A close-up of digits and digital data flows, symbolising the scale of the breach and the need to protect one's information.

Photo: Unsplash — 24 million contracts, 100,000 IBANs released: the scale of the breach calls for individual vigilance.

The role of operators in the chain of trust

This case shines a light on a fundamental issue: the chain of trust between a subscriber and their operator. When you take out a plan, you entrust a third party with sensitive data: identity, IBAN, usage, geolocation. This trust demands, in return, flawless security hygiene and the automatic purge of data after termination.

The GDPR, in its Article 5, already imposes this principle of storage limitation. The CNIL's deliberation now clarifies zero tolerance: an operator that keeps fifteen million customer records for five years without operational justification is taking a major financial risk.

It is also, indirectly, good news for the ecosystem. The other operators — Orange, SFR, Bouygues Telecom — are now forced to review their own procedures, on pain of a comparable sanction. And the regulator has a solid precedent to act on.

The bottom line

  • €42 million in fines (€27M for Free Mobile, €15M for Free) handed down by the CNIL on 8 January 2026.
  • The breach concerns 24,633,469 contracts, including 19.4 million mobile and 5.2 million fixed contracts.
  • Three GDPR breaches sanctioned: excessive retention, insufficient VPN security, too vague a notification.
  • Free has lodged an appeal with the Conseil d'État; the case is not closed.
  • For subscribers: monitor your bank accounts, beware of targeted phishing, strengthen your passwords.

To send a free and anonymous SMS to a loved one without handing your data to a third-party service, our SMS sending form remains accessible everywhere, with no sign-up and no trace. For any question about your personal data, you can also read our FAQ, our legal notice or contact us.

#GDPR#Free#CNIL#Cybersecurity#Personal data

Related articles

Send your SMS for free

100% free service, no sign-up and no ads. Send unlimited SMS to France.

Send an SMS
bg wave