Free 2024: 24 Million Accounts Exposed, IBANs Included, and CNIL's Record Fine
> TL;DR: In October 2024, French telecom Free and its mobile arm Free Mobile suffered one of the largest cyberattacks in French telecom history: 24 million contracts exposed, with IBANs leaked for customers who subscribed to both internet and mobile plans. In 2026, CNIL imposed a record 42 million euro fine for a failure to secure data adequately and for inadequate post-incident communication.
What happened
In October 2024, an attacker accessed Free's systems and exfiltrated personal data tied to 24 million contracts. For customers who had both an internet and a mobile plan, IBANs were also exposed — a particularly sensitive piece of banking data because, combined with other information, it enables direct debit fraud attempts.
Why CNIL sanctioned so heavily
The 42 million euro fine does not target the existence of the breach itself — a security incident is not in itself a GDPR violation — but two specific failures:
Why the IBAN exposure changes everything
Unlike a password, an IBAN cannot be easily "reset" after a leak — closing a bank account and opening a new one has serious consequences for the user. Exposing an IBAN alongside identity data (name, address, contract number) gives an attacker everything needed to attempt fraudulent direct debits or highly convincing phishing campaigns impersonating the telecom operator or the bank.
For any SaaS vendor storing banking details (payroll, billing, customer direct debits), this incident illustrates why such data must be handled at a higher protection tier than regular contact data: encryption at rest, strictly limited access, and tokenization through a payment provider rather than plaintext application-side storage whenever possible.
What this means for French vendors
This fine confirms a trend CNIL has been building since 2024-2025: sanctions no longer focus only on the scale of a breach, but on whether security measures were proportionate to the sensitivity of the data processed, and on the quality of the incident response. A vendor processing payroll data, IBANs, or health data must be able to demonstrate specific measures for these categories, not a generic security baseline.
What CleanIssue checks for
During an external review, we specifically test the protection of financial and identity data stored by your application — encryption, access control, API exposure — as well as mass-exfiltration scenarios, exactly the type of flaw that enabled this 24-million-account breach.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
DGFiP Breached by ZeroBytes: Inside France's Biggest Tax Data Leak of 2026
France's tax authority (DGFiP) confirmed unauthorized access to its information system: impersonated agent credentials, no blanket MFA, and over 2 million people potentially exposed through the cadastral records server.
France Travail 2024: 43M French Citizens Leaked, What Really Happened
Technical breakdown of the France Travail data breach in 2024: how 43 million records were exposed, timeline, and lessons learned.
SFR 2024-2025: Two Breaches in One Year, the Second via an Internal Management Tool
SFR suffered two separate security incidents in under 18 months: a breach affecting 3.6 million customers in September 2024, then a new compromise in late 2025. What both episodes reveal about the risk of internal tools.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.