Back to the archive

The encyclopedia · Advertising & PR · Marketing decision · 2024–2026

Free held 24 million customers' bank details too long. A breach cost it €42M.

A weak VPN let the attacker in. CNIL found Free had hoarded millions of records for no reason and told customers too little. The fine: €42M.

Free · Free Mobile · 2024-10

What happened

In October 2024 an attacker infiltrated the information systems of Free and Free Mobile, the two telecom arms of Xavier Niel's Iliad group, and reached the personal data of 24 million subscriber contracts — including the bank account numbers, or IBANs, of customers who used both services. It was one of the largest breaches of a French consumer brand. More than 2,500 of those customers complained to the data-protection regulator, the CNIL.

When the CNIL ruled, on 13 January 2026, it fined the two companies €42 million in total — €27 million for Free Mobile and €15 million for Free. The regulator's findings went beyond the hack itself. Free Mobile, it said, had kept millions of subscriber records for far longer than it had any reason to, breaching the GDPR rule that data be held only as long as needed. The bigger the hoard, the bigger the breach.

The security failings were specific. The VPN used to access the systems was not authenticated robustly enough; the tools meant to spot abnormal behaviour did not work; the measures protecting confidentiality were inadequate. In other words, the data was both over-collected and under-guarded.

Then came the part that made it a brand failure rather than an IT one. Free's email notifying customers of the breach, the CNIL found, left out information people needed — it did not let them understand the consequences or what to do to protect themselves. A company that holds 24 million customers' bank details and then cannot tell them clearly what was taken has failed at the relationship, not just the firewall.

Why it happened

  • The data was over-collected and over-retained. Free Mobile kept millions of records it had no justification to hold, so when the attacker got in, the haul was enormous by design.
  • Basic security was left weak. A VPN with insufficient authentication and ineffective monitoring left the door open; the breach was not sophisticated so much as unopposed.
  • The notification failed the customer. The breach email omitted what people needed to understand the risk and protect themselves, turning a security incident into a trust incident.
  • The regulator treated data stewardship as a brand obligation. CNIL priced the whole failure — security, retention and disclosure — at €42 million: holding customer data is holding customer trust.
What it cost€42M fine; 24M contracts, including IBANs, exposedcostly

The lesson

Collect only the customer data you need, delete it when you don't, and guard what's left — because a regulator now prices a leak not as an accident but as a breach of the customer relationship.

Aftermath

The CNIL's two decisions of 13 January 2026 totalled €42 million, among the larger French data-protection penalties, and followed more than 2,500 complaints from affected subscribers. For Free, a brand built on undercutting incumbents, the ruling attached a different kind of cost to its scale: the more customers it signed up, the more it owed when their data was left exposed.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →