Back to blog
Famous hacksFranceGDPRdata breach

Free 2024: 24 Million Accounts Exposed, IBANs Included, and CNIL's Record Fine

Published on 2026-08-176 min readCleanIssue

> TL;DR: In October 2024, French telecom Free and its mobile arm Free Mobile suffered one of the largest cyberattacks in French telecom history: 24 million contracts exposed, with IBANs leaked for customers who subscribed to both internet and mobile plans. In 2026, CNIL imposed a record 42 million euro fine for a failure to secure data adequately and for inadequate post-incident communication.

What happened

In October 2024, an attacker accessed Free's systems and exfiltrated personal data tied to 24 million contracts. For customers who had both an internet and a mobile plan, IBANs were also exposed — a particularly sensitive piece of banking data because, combined with other information, it enables direct debit fraud attempts.

Why CNIL sanctioned so heavily

The 42 million euro fine does not target the existence of the breach itself — a security incident is not in itself a GDPR violation — but two specific failures:

  • Breach of the security obligation (GDPR Article 32): insufficient technical measures allowed access and exfiltration at this scale, particularly around IBAN storage and protection.
  • Insufficient post-incident communication: CNIL found that the information provided to affected individuals did not match the sensitivity of the exposed data, slowing victims' ability to protect themselves against fraud.
  • Why the IBAN exposure changes everything

    Unlike a password, an IBAN cannot be easily "reset" after a leak — closing a bank account and opening a new one has serious consequences for the user. Exposing an IBAN alongside identity data (name, address, contract number) gives an attacker everything needed to attempt fraudulent direct debits or highly convincing phishing campaigns impersonating the telecom operator or the bank.

    For any SaaS vendor storing banking details (payroll, billing, customer direct debits), this incident illustrates why such data must be handled at a higher protection tier than regular contact data: encryption at rest, strictly limited access, and tokenization through a payment provider rather than plaintext application-side storage whenever possible.

    What this means for French vendors

    This fine confirms a trend CNIL has been building since 2024-2025: sanctions no longer focus only on the scale of a breach, but on whether security measures were proportionate to the sensitivity of the data processed, and on the quality of the incident response. A vendor processing payroll data, IBANs, or health data must be able to demonstrate specific measures for these categories, not a generic security baseline.

    What CleanIssue checks for

    During an external review, we specifically test the protection of financial and identity data stored by your application — encryption, access control, API exposure — as well as mass-exfiltration scenarios, exactly the type of flaw that enabled this 24-million-account breach.

    Key takeaways

  • Banking data (IBANs) requires a higher protection tier than contact data — encryption, tokenization, minimal access.
  • Proportionality of security measures to data sensitivity is now a central CNIL sanction criterion, not just the volume of the breach.
  • Post-incident communication quality is assessed alongside technical security — an incident response plan is no longer optional.
  • Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Written by CleanIssue
    Reviewed on 2026-08-17

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit