[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8kkwj36g13tp":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488251e0","FreeMobile","Free Data Breach","free","free.fr","2024-10-17T00:00:00.000Z","2025-05-27T07:03:21.000Z","2026-07-20T06:09:10.353Z","Database leak","https:\u002F\u002Fwww.cnil.fr\u002Fen\u002Fsanction-free-2026",[15,17],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffree-frances-second-largest-isp-confirms-data-breach-after-leak\u002F",13926173,"known",null,"unknown","Critical",[24,25,26,27,28,29,30],"Email addresses","Bank account numbers","Dates of birth","Genders","Names","Phone numbers","Physical addresses","\u003Cp>The \u003Cstrong>Free data breach\u003C\u002Fstrong> is a verified incident dated 17 October 2024 involving 13,926,173 unique email addresses.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The publicly distributed records contained names, physical addresses, phone numbers, genders, dates of birth and bank account numbers belonging to some subscribers. The count of \u003Cstrong>13,926,173 unique email addresses\u003C\u002Fstrong> represents the verified breach corpus; it is not the total number of contracts accessed or records containing an IBAN. Combining an address, birth date, phone number and email can make support impersonation, targeted phishing, fraudulent SIM replacement stories and account takeover attempts more credible. An IBAN alone is not generally sufficient to initiate a direct debit, but it can support fake payment instructions, unauthorised collection attempts or bank impersonation when paired with identity details.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>An attacker entered information systems operated by Free and Free Mobile in October 2024 and accessed subscriber-management data. A regulatory investigation described the scope as 24 million subscriber contracts. That figure measures contracts and cannot be directly compared with unique emails in the verified public corpus. The 19.2 million customer records and 5.11 million IBANs advertised by the seller are attacker claims, not a verified unique-account count. Investigators found that VPN authentication used for remote access was not sufficiently robust and that controls intended to detect abnormal behaviour were ineffective. The material was first advertised for sale and later released publicly. Free stated that passwords, payment card information, and the contents of emails, text messages or voicemail were not affected. Regulatory penalties totalling €42 million were issued in 2026 over security safeguards, breach notification and, for Free Mobile, data-retention practices. The findings show that access control, monitoring and data-lifecycle weaknesses all contributed to the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people most directly exposed are those who had an active Free or Free Mobile subscription, together with former subscribers whose information remained stored. A subset of fixed-line customers had IBAN data in the affected material, increasing financial impersonation risk, but bank account numbers should not be assumed to appear in every record. People whose birth date, address and phone number appeared together face a greater chance of criminals guessing verification answers or persuading support staff to change an account. Anyone using the same email address across other services should watch for attacks that move between platforms. There is no verified finding that passwords were exposed, yet fake reset messages remain a likely lure.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Sign in to your Free account by typing the official address yourself or using the trusted application, not by following a link in an unexpected message. Check contact and subscription settings for changes you did not make. Do not provide a birth date, IBAN, identity document or one-time code to anyone claiming to represent Free, a bank or a public authority. \u003Cstrong>Monitor bank activity and direct-debit mandates closely\u003C\u002Fstrong>; report an unfamiliar collection promptly and revoke the relevant mandate. If your mobile line loses service, verification messages stop arriving or an unexplained transfer notice appears, ask the operator to investigate a possible SIM swap. Because password exposure was not confirmed, avoid unsolicited reset links. If the Free password is reused elsewhere, replace it with a unique password on every account and enable two-step verification. Keep screenshots, dates, sender details and payment references for suspicious communications.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A birth date or historical address cannot be rotated like a password, so protection should continue beyond the first weeks. Enable banking alerts for small transactions, review authorised direct-debit collectors and take unexpected credit or telecom applications seriously. Secure the email account with a strong unique password, then check recovery phone numbers, backup addresses and active sessions regularly. If the operator account offers an additional security code or restrictions on sensitive changes, turn them on. Legitimate institutions do not pressure customers by phone to transfer money or disclose a one-time code; end the conversation and call a published number independently. Tell family members about bank and telecom impersonation, especially when a caller already knows an address or account history. Create a written record with the bank, operator and appropriate reporting service if suspicious activity can be connected to the incident.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Enter an email address in the LeakData.io search to check whether it matches the Free breach record. A match does not mean that every listed data type appeared in your record; IBANs affected only a defined subset of customers. An empty result does not prove that no information was accessed, because the incident scope and verified public corpus use different counting units. Repeat the check for other email addresses previously used with Free services. If a match appears, secure the email account, operator profile and banking activity first, then review important accounts that rely on the same contact details. Never provide a password, IBAN or identity document in response to a search result. When a message refers to the breach, verify the sender domain, destination of every link and purpose of the request instead of trusting the displayed name. Periodic checks and quick reporting can limit phishing, identity misuse and financial fraud connected with the exposed information.\u003C\u002Fp>","","Free Data Breach (13.9 Million Reported Records)","Free Data Breach. 13.9 Million reported records were reported. Reported data: Email addresses, Bank account numbers, Dates of birth. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Ffree_fr.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":20},"Free","Telecommunications \u002F ISP","France"]