France Fines Free and Free Mobile €42 Million for Data Breach
- Securityish
- Privacy & Personal Security
Quick Summary
The Securityish Brief
The CNIL issued a collective fine of €42 million ($48.9 million) to Free and Free Mobile, two telecom companies owned by Iliad Group, due to serious GDPR violations. The fines were a result of a data breach that occurred in October 2024, compromising the personal data of more than 24 million individuals, including financial information such as IBANs.
The breach was initiated on September 28, 2024, when attackers accessed Free’s network through a VPN. They later connected to Free Mobile’s subscriber management tool, MOBO, which allowed them to search for customer data. The attackers began exfiltrating records on October 6, 2024, affecting 24,633,469 contracts, including 19,460,891 Free Mobile and 5,172,577 Free contracts.
Free Mobile had approximately 15.5 million subscribers at the time, while Free had around 7.6 million. The fines were divided into €27 million ($31.4 million) for Free Mobile and €15 million ($17.4 million) for Free, reflecting the companies’ financial performance in 2024.
CNIL found that the companies failed to implement basic security measures, such as a robust authentication procedure for VPN access, and lacked effective monitoring for abnormal behavior within their systems. Additionally, the companies did not adequately communicate the breach to affected users or comply with data retention laws.
This incident underscores the critical importance of robust cybersecurity measures and compliance with data protection regulations, as the consequences of negligence can lead to significant financial penalties and loss of customer trust.
Implications for Users and Organizations
Organizations must take this incident as a warning to review their security protocols, particularly around VPN access and data retention policies. The breach illustrates how inadequate security can lead to large-scale data exposure, affecting millions of users.
Everyday users should be vigilant about their personal information, especially if they are customers of affected companies. Monitoring bank statements and credit reports can help detect any unauthorized transactions resulting from such breaches.
Companies should also prioritize transparent communication with customers regarding data breaches, ensuring that users are informed about the nature of the breach and the steps they can take to protect themselves.
Key Takeaways
- Review your organization’s VPN security protocols to ensure robust authentication measures are in place.
- Implement regular monitoring for abnormal behavior within your information systems.
- Establish clear data retention policies to comply with GDPR and other regulations.
- Communicate transparently with customers about data breaches and provide guidance on protective measures.
- Encourage users to monitor their financial accounts for any unauthorized activity following a breach.
Key Terms & Concepts
- GDPR: GDPR stands for General Data Protection Regulation, a regulation in EU law on data protection and privacy.
- IBAN: IBAN stands for International Bank Account Number, used to identify bank accounts across countries.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.