France fines Free Mobile €42 million over 2024 data breach incident
嗯,用户让我总结这篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我需要快速浏览文章内容,抓住主要信息。 文章讲的是法国的数据保护机构CNIL对Free Mobile及其母公司Free罚款4200万欧元,原因是他们没有充分保护客户数据。发生了数据泄露事件,影响了近2300万用户,黑客利用管理工具窃取了敏感信息。调查发现Free在数据安全、通知和数据保留方面违反了GDPR规定。此外,法国其他电信公司也发生了类似事件。 接下来,我需要将这些信息浓缩到100字以内。重点包括:罚款金额、公司名称、数据泄露影响人数、违反GDPR的具体条款、以及后续事件。 可能的结构是:法国监管机构因数据泄露和GDPR违规对Free Mobile及其母公司罚款4200万欧元,涉及2300万用户,随后其他电信公司也发生类似事件。 检查一下是否在100字以内,并且没有使用特定的开头词。确保信息准确且简洁。 </think> 法国监管机构因数据泄露和GDPR违规对Free Mobile及其母公司罚款4200万欧元,涉及2300万用户。随后,法国其他电信公司也发生类似事件。 2026-1-14 20:0:27 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

France fines Free Mobile €42 million over 2024 data breach incident

The French data protection authority (CNIL) has imposed cumulative fines of €42 million on Free Mobile and its parent company, Free, for inadequate protection of customer data against cyber threats.

The company is the second-largest internet service provider in France and suffered a data breach in October 2024, exposing information of nearly 23 million mobile and fixed subscribers.

The hackers targeted the firm’s management tool and stole sensitive customer information to sell it later on a hacker forum. The offer came from an account named 'drussellx' and claimed that the attack impacted 19.2 million customers, and that the details included IBANs for roughly 25% people.

Wiz

Following an investigation into the incident, CNIL concluded that, despite Free improving its cybersecurity stance after the incident, its previous negligence violated several GDPR rules.

"Following a large number of complaints (more than 2,500 to date) from individuals affected by this data breach, the CNIL carried out an inspection which revealed breaches of several obligations under the General Data Protection Regulation (GDPR) attributable to FREE MOBILE and FREE, each of which is the data controller for its own subscribers," the French agency said

Specifically, the following violations have been found:

  1. Failure to ensure data security (Article 32 GDPR) – Free Mobile and Free had inadequate security measures in place, including weak VPN authentication for employees' remote access and ineffective detection of abnormal activity, which which enabled the attack.
  2. Failure to properly inform affected individuals of the breach (Article 34 GDPR) - Although the companies notified users, the emails lacked detailed information and did not clearly explain the consequences of the breach or what steps should be taken to mitigate the risk.
  3. Excessive retention of personal data (Article 5(1)(e) GDPR) – Free Mobile kept personal data of millions of former subscribers for a longer period than was necessary, and did not sort or delete it in due time, beyond what was justified for accounting purposes.

The CNIL ordered both companies to complete their newly implemented security measures within three months, and required Free Mobile to finish sorting and removing excess customer data within six months.

After the breach at Free Mobile, France experienced more customer-exposing or service-disrupting incidents on large telecommunication service providers.

In July 2025, Orange France announced that it had detected a breach on its systems, causing operational disruptions. A month later, Bouygues Telecom suffered a data breach that exposed the sensitive data of 6.4 million customers.

Wiz

Secrets Security Cheat Sheet: From Sprawl to Control

Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

Get the cheat sheet and take the guesswork out of secrets management.


文章来源: https://www.bleepingcomputer.com/news/security/france-fines-free-mobile-42-million-over-2024-data-breach-incident/
如有侵权请联系:admin#unsafe.sh