CNIL sanction against Free: a fine of 42 million euros after the 2024 cyberattack

Have you ever thought about the consequences of a security breach in a company managing millions of personal data? Imagine the pressure and stakes when realizing that this sensitive information has been compromised. Free, a major player in telecommunications, finds itself in this delicate situation following the cyberattack of October 2024. Discover how this case took a decisive turn with the sanction imposed by the CNIL.

The 3 key facts not to miss

  • The CNIL imposed a fine of 42 million euros on Free for GDPR violation.
  • 24 million contracts were compromised during the cyberattack, exposing critical personal data.
  • Free must strengthen its security measures and review its data management within strict deadlines.

The CNIL sanction

On January 14, 2026, the CNIL announced a massive fine of 42 million euros against Free, a decision made in response to the devastating cyberattack of October 2024. Free Mobile was ordered to pay 27 million euros, while Free must pay 15 million euros. This financial sanction highlights the seriousness of the situation, where flaws in the protection of personal data were identified.

Impact of the cyberattack

🚀 Les 8 outils que la rédaction EmarketerZ recommande en 2026

Chaque semaine, nous sélectionnons les solutions les plus utiles pour les professionnels du digital : IA, productivité, marketing, création de contenu et business. Voici les outils que nous recommandons actuellement.

☁️ pCloud – Le stockage cloud sécurisé avec une offre à vie.
Sauvegardez vos fichiers, photos et documents importants avec plusieurs centaines de Go ou plusieurs To disponibles.
→ Découvrir l'offre pCloud

🛒 Shopify – Créez votre boutique e-commerce sans coder.
Une solution complète pour lancer, gérer et développer votre activité en ligne.
→ Tester Shopify gratuitement

🤖 Jasper – L'assistant IA pour accélérer votre marketing.
Création de contenus, campagnes publicitaires et idées marketing : gagnez du temps grâce à l'intelligence artificielle.
→ Découvrir Jasper

🎬 CapCut Pro – Le montage vidéo dopé à l'IA.
Créez rapidement des vidéos professionnelles avec des outils avancés et automatisés.
→ Tester CapCut Pro

📊 HubSpot CRM – Le CRM idéal pour structurer votre croissance.
Gérez vos prospects, vos ventes et vos campagnes marketing depuis une seule plateforme.
→ Découvrir HubSpot CRM

🧠 MindManager – Organisez vos idées et vos projets efficacement.
Un outil puissant pour créer des mind maps, structurer vos stratégies et mieux collaborer.
→ Découvrir MindManager

🇬🇧 Gymglish – Améliorez votre anglais professionnel chaque jour.
Des cours personnalisés et courts pour progresser facilement, quel que soit votre niveau.
→ Profiter de l'essai gratuit

🌍 Preply – Apprenez une langue avec un professeur particulier.
Trouvez un enseignant adapté à vos objectifs et progressez à votre rythme.
→ Trouver votre professeur

✨ Une sélection pensée pour les entrepreneurs, marketeurs, créateurs et passionnés de technologie.

The cyberattack exposed 24 million contracts, endangering sensitive information such as customers’ banking details. A CNIL investigation revealed that the hacker was able to access Free’s servers through insufficiently secured VPN connections. Despite the presence of monitoring systems, the intrusion went unnoticed, thus exposing the weaknesses of the company’s security infrastructure.

Crisis management and data protection

Beyond technical flaws, Free’s crisis management was criticized for its lack of clarity and transparency. Although the operator informed its customers by email and set up a toll-free number, these actions were not enough to reassure subscribers or provide them with concrete measures to protect themselves. Furthermore, Free Mobile was criticized for retaining former customers’ data without legitimate reason, thereby increasing security risks.

Upcoming obligations for Free

The CNIL has set strict deadlines for Free to correct its shortcomings. Free Mobile has six months to clean up its obsolete databases. Meanwhile, Free must finalize its new security measures within three months. These requirements aim to ensure that the operator meets the minimum security standards to protect its customers’ personal data.

Context on Free and the CNIL

Free, founded by Xavier Niel, is one of the leading telecommunications providers in France. The company has always been at the forefront of innovation in the sector, but this cyberattack highlights significant cybersecurity challenges.

The CNIL, on the other hand, is the French regulatory authority for data protection. Responsible for ensuring compliance with the GDPR, it plays a crucial role in enforcing privacy protection rules in France. Its recent actions against Free underscore the growing importance of data security in today’s digital environment.

Source:

[New] 4 ebooks on digital marketing available for free download

Did you enjoy this article? Receive our next articles by email.

Sign up for our newsletter, and you will receive an email every Thursday with the latest articles published by experts.

Other articles on the same topic:

Leave a Reply

Your email address will not be published. Required fields are marked *