Free: the fine is being argued at the Conseil d'État, the phishing carries on
In October 2024, an attacker left Free's information system with the data of 24 million subscriber contracts, IBANs included. In January 2026, the French data protection authority fined the operator 42 million euros for elementary security failings and for keeping, without justification, the data of millions of former subscribers. My data is in that file, and no decision by the regulator will take it out.

The email arrived in my inbox some time ago. Free Mobile was demanding an unpaid invoice of 9.99 euros, failing which my line would be suspended. The sender was called freemobile-regularisation, on a domain that had nothing to do with the operator, and the link led, after a series of redirects, to a bank card form of entirely credible appearance.
My data was in the file stolen from Free in October 2024, like that of millions of French people. Spotting a phishing attempt is part of my job, and this one did not cost me a euro. What occupies me is how much longer this mail will keep arriving, at my address and at those of the millions of subscribers who have no reason to be dragged into it, and nobody, not Free, not the CNIL, not the Conseil d'État, has the means to answer that.
A VPN, a subscriber management tool, twenty-four million contracts
The intrusion began on 28 September 2024. According to the CNIL decision, the attacker connected to the operator's VPN, the private network that lets employees work remotely as though they were on the premises, then to the subscriber management tool, where they remained for several weeks. Free publicly confirmed the attack on 26 October 2024 and filed a complaint with the public prosecutor. The categories of data involved, as the operator confirmed them, cover surname and first name, email and postal addresses, phone number, date and place of birth, subscriber identifier, contractual information and, for some customers, the IBAN. Passwords and bank card numbers are not on the list.
The seller of the file announced 19 million subscribers and 5.11 million IBANs. Those figures were claims, and articles published a year later still presented them as established. The confirmed figure arrived with the CNIL sanction, and it is higher: 24 million subscriber contracts. The count covers contracts, and a single customer may hold several, which rules out deducing an exact number of people from it. In a country of fewer than 70 million inhabitants, the order of magnitude does without that precision.
In June 2025, Have I Been Pwned, the free service that lets anyone find out whether their email address appears in a known breach, took in nearly 14 million addresses from this file. The file is circulating, it is indexed, and anyone can consult it to check their own exposure as readily as to select targets.
What the CNIL sanctioned belongs to the basics
On 14 January 2026, the CNIL made two fines public, 27 million euros for Free Mobile and 15 million euros for Free, 42 million in total. None of the failings it found describes a sophisticated attack.
The first concerns the front door. The CNIL writes that the VPN authentication procedure of both companies, used in particular for remote work, was « not sufficiently robust ». The lawyers who analysed the decision read into that the absence of multifactor authentication, meaning a second piece of proof, a code or a physical key, required on top of the password. The European NIS2 directive names it among the measures expected of companies, and it is the first one I ask for in a compliance engagement, because it costs little and closes a great deal. The second security failing concerns detection: the measures meant to spot abnormal behaviour on the information system were, according to the CNIL, « ineffective ». An attacker was therefore able to move for several weeks inside the tool holding every subscriber's data without anything sounding.
The third failing concerns informing the people affected. The email sent to subscribers did not contain all the information the GDPR requires, and did not allow them to clearly understand the concrete consequences of the breach or the steps to take to protect themselves. The fourth, specific to Free Mobile, covers retention periods: the company had put no measures in place to sort former subscribers' data and keep only what was necessary for accounting purposes.
The CNIL attached two injunctions to the fines, three months to complete the security work and six months for Free Mobile to finish sorting and deleting the data kept in excess. Free denounced a decision of « unprecedented severity, out of all proportion » with precedent and announced it would take the matter to the Conseil d'État.
The data that should have been erased
The French commercial code requires accounting documents to be kept for ten years. That is the most generous justification an operator has for keeping a trace of a departed subscriber, and Free Mobile undertook before the CNIL to limit itself to it. Beyond ten years, no basis holds. According to the lawyers who analysed the decision, Free Mobile's database nonetheless still held close to three million contracts terminated more than ten years earlier, within a far larger set of ended contracts kept beyond what was necessary.
That is the irony the coverage of the sanction let slip. Excessive retention was treated as an administrative failing alongside the real subject, security. It is half of it. Erased data cannot be exfiltrated, cannot be resold and cannot serve to make a fake reminder email credible. Every line a former subscriber should never have left in the management tool was a line available to the attacker of September 2024, and it is available today to everyone who bought or downloaded the file.
The published decision does not say how many former subscribers were in the stolen batch. The reasoning does without that figure. Data minimisation, the GDPR principle requiring that only the strictly necessary be kept, is first of all a security measure, the only one still protecting you when every other one has given way. The CNIL sanctioned that retention in January 2026, and the bill for that retention is being collected today by the scammers.
Why does a data breach have no expiry date?
After a password breach, the advice fits on one line: change it, turn on two-factor authentication, and the exposure falls to almost nothing within minutes. The value of the stolen data expires at the speed of the victim's reaction.
The Free file contains almost nothing of that nature. A name does not change, nor does a date or a place of birth. A postal address changes at the pace of house moves, an email address is often kept for decades because it is attached to every other account. The IBAN, finally, is changed on a simple request to your bank, but you then have to inform your employer, your suppliers and every organisation that takes a direct debit, and almost nobody puts themselves through that chore because their phone operator was hacked. The half-life of this file, the time after which half the information no longer matches reality, is therefore counted in years, perhaps in decades.
For a scammer, this data serves three purposes. It allows targeting first, since the file says who is a Free customer and at what address to reach them. It then makes the message credible, because an email that knows your date of birth or displays your IBAN passes the first filter of suspicion effortlessly. The IBAN, finally, can serve directly to sign a fraudulent direct debit mandate or to subscribe to a service in the victim's name. None of those uses expires with the closing of an administrative procedure.
Three waves in fourteen months
The first widely documented campaign arrived in August 2025. The email reproduces Free's visual identity, contains no spelling mistakes, invokes a supposed new European regulation and asks you to verify your bank details before 26 August. It displays, in clear text, the recipient's real IBAN. The file is no longer merely on sale, it is being used.
At the end of October 2025, a new wave repeated the same scenario, and Free published an alert on its support site. The central sentence of that alert deserves to be remembered by every subscriber: « Free never displays your bank details in clear text in its emails and texts ». The operator provides there a simple, verifiable criterion, which would have had every place in the October 2024 notification.
The third wave is the one from 2026, the one that arrived in my inbox. It differs from the previous ones on one point: the message is generic, and nothing establishes that its authors are using the stolen file. They do not need to. The breach made Free a brand whose subscribers know their data is out there, and who have already received fraudulent emails displaying their own IBAN. The amount of 9.99 euros is calibrated not to trigger any thought, low enough to be settled on the spot, close enough to a real plan price to seem plausible. The threat of line suspension adds urgency, and urgency is what short-circuits verification.
The regulator's file has a closing date, the subscriber's does not
Everything in this affair that belongs to compliance carries a date. The breach is recorded in October 2024, the sanction made public on 14 January 2026, the security injunction falls due three months after its notification, the purge injunction six months after. The appeal to the Conseil d'État will produce a dated decision, confirming, reducing or quashing the amount. Each step produces a document, and each document can be filed away.
The subscriber's situation produces no document and cannot be filed away. There exists no injunction ordering the file to disappear from the forums where it was resold, no decision rendering an IBAN unusable to a scammer, no deadline after which a date of birth stops being exploitable information. The fine goes to the public treasury, and the 24 million contracts concerned receive none of it.
The failure to inform subscribers takes on its real weight here. The CNIL held that the 2024 notification did not allow subscribers to understand the concrete consequences of the breach or the steps to take. The people receiving a fake 9.99 euro invoice today are precisely those who should have learned, back in October 2024, that Free never displays an IBAN in an email, that their bank details could serve for fraudulent direct debits and that their bank could protect them from it. The injunctions made public concern the security of the system and the purge of the data. Informing the people affected, judged insufficient, is not among them.
How do you recognise a fake Free email?
The first reflex is to read the real domain, and to read it correctly. In a web address, the domain that counts is the part immediately before the final extension: in mobile.free.fr, it is free.fr, which belongs to the operator. In espace-free-mobile.pro, it is espace-free-mobile.pro in its entirety, which anyone can buy for a few euros, and the word « free » in it is mere decoration. The sender's address is read the same way: my fake Free Mobile ended in knowledgegrowthcenter.help, which was enough to disqualify the message. An official-looking domain guarantees nothing either, and the Revolut affair showed that a genuine government domain is enough to obtain passports when nobody verifies the request itself.
The second reflex is never to follow the link. If a message mentions your account, open the Free Mobile app or type mobile.free.fr into the address bar yourself, and check whether an invoice really is pending. If in doubt, Free Mobile customer service answers on 3244. Remember too the criterion Free itself published: an email or a text displaying your IBAN in clear text does not come from the operator. Fraudulent emails are reported to Signal Spam, texts to 33700.
If your IBAN was in the file, the most effective protection is negotiated with your bank. You can ask it to set up a whitelist, which authorises only direct debits from named creditors, a blacklist, which blocks specific creditors, or a complete block on direct debits. The Banque de France points out that an authorised direct debit can be contested within eight weeks of the debit, and that an unauthorised debit, with no valid mandate, can be contested for thirteen months. Watching your statements remains the only way to make use of that second deadline.
What remains open
The purge injunction addressed to Free Mobile carried a six-month deadline from the notification of the January 2026 decision, and that deadline has passed. The CNIL should make public its finding on compliance, with the number of contracts actually deleted, because that is the only measure in the whole affair that reduces future exposure.
Free should publish the number of former subscribers whose data was in the exfiltrated file. That figure would say how many people, gone for years, are living today with the consequences of data the operator no longer had the right to keep.
A supplementary notification, complete this time, should be sent to the holders of the 24 million contracts. It would fit on one page: Free never displays an IBAN in a message, the official site is mobile.free.fr, 3244 answers, and your bank can block direct debits from strangers. An alert on a support site is no substitute for a message received in your inbox.
The Conseil d'État, finally, will rule on the amount. Whatever it decides, it will not touch the file.
On 28 September 2024, an attacker came in through Free's VPN. On 14 January 2026, the CNIL made its sanction public, and a few months later a fake Free Mobile was demanding 9.99 euros from me. My name and my date of birth have not changed.
Further reading
- France's tax authority knew in late June. You found out on 13 August
- A week of data breaches in France: the file nobody wanted
- 153 million identity documents for sale, and not one stolen from a careless user
- A genuine government domain was enough to obtain passports and ten years of Bitcoin history
- The only backup that counts is the one you have already restored
- Practical steps against phishing on etrecyber.fr
Sources
- CNIL, Violation de données : sanction de 42 millions d'euros à l'encontre des sociétés FREE MOBILE et FREE, statement of 14 January 2026, and the restricted committee deliberations SAN-2026-001 (Free Mobile) and SAN-2026-002 (Free) of 8 January 2026, published on Légifrance.
- Jérôme Boursier, Malwarebytes, Free Mobile phishing texts appear days after data breach, 1 October 2026.
- Free, Assistance, Soyez vigilant : une campagne de phishing est en cours, article 1775; Univers Freebox, Free alerte ses abonnés face à une nouvelle vague d'arnaques les visant, 30 October 2025.
- Mac4ever, Fuite chez Free : vos données bancaires utilisées dans une nouvelle arnaque redoutable, 25 August 2025.
- MacGeneration, Free confirme un large vol de données de ses clients, 26 October 2024; Génération NT, La fuite de Free chez Have I Been Pwned, June 2025.
- Haas Avocats, Violation de données chez Free : sanction record de la CNIL, and Village de la Justice, Bernard Rineau and Sanya Hamou Maamar, Violation de données : la CNIL sanctionne Free Mobile et Free, 2026, for the sequence of the intrusion and the volumes of terminated contracts retained.
- Le Club des juristes and Économie Matin, January 2026, for Free's reaction and the announcement of the appeal to the Conseil d'État.
- Banque de France, Foire aux questions : le prélèvement SEPA.
- Directive (EU) 2022/2555 of 14 December 2022, known as NIS2, Article 21; French commercial code, Article L123-22.
Frequently asked questions
How do I know whether my data is part of the Free breach?
Free notified the subscribers concerned by email in the autumn of 2024. If you no longer have that message, the Have I Been Pwned service lets you check free of charge whether your email address is among the nearly 14 million addresses from the file. A former subscriber may be affected, since the CNIL faulted Free Mobile for keeping the data of millions of departed customers.
What can a scammer do with my IBAN?
They cannot take money out of your account with that number alone. They can, however, use it to sign a fraudulent direct debit mandate, subscribe to a service in your name, or make a fake email credible by displaying it. A whitelist of creditors requested from your bank neutralises most of the direct debit risk.
Does the fake 9.99 euro invoice really use the stolen data?
Nothing establishes it. The message is generic and no published analysis formally links it to the file. The August and October 2025 waves did display recipients' real IBANs, which proves the file is being exploited, and a generic campaign benefits from an audience that knows its data is compromised.
Has Free paid the 42 million euro fine?
Free announced in January 2026 that it would take the matter to the Conseil d'État to contest a sanction it considers disproportionate. The outcome of that appeal will concern the amount and the regularity of the sanction. It will change nothing about the data already in circulation.
Should I change my IBAN after the breach?
The bank will do it on request, but nothing requires it in the absence of established fraud, and the process means updating every direct debit. A whitelist of creditors, regular monitoring of statements and contesting any unknown debit, within eight weeks if it was authorised and within thirteen months if it was not, cover most of the risk. Changing your IBAN becomes relevant if fraudulent debits recur.
What are Free Mobile's official channels?
The Free Mobile app, the site mobile.free.fr typed directly into the address bar, the site assistance.free.fr and customer service on 3244. Free states that it never displays bank details in clear text in its emails and texts, which is enough to rule out a good share of fake messages.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
