One of the largest cyberattacks in the history of French telecoms

At the beginning of October 2024, Free Mobile, the mobile subsidiary of the Iliad group, confirmed that it had been the victim of an exceptionally large cyberattack. Nearly 19 million customers — representing the majority of the operator's client file — had their personal data compromised and exfiltrated by a malicious actor.

The information was made public after a cybercriminal offered the entirety of the file for sale on a dark web forum, triggering the mobilization of Free's security teams and the initiation of an investigation by French authorities.

What data was stolen?

According to information provided by Free and reported by the press, the exfiltrated data includes:

  • First and last name of subscribers
  • Complete postal address
  • Email address
  • Phone number
  • Date of birth
  • For a portion of the customers: IBAN number (bank account identification)

Free clarified that no sensitive banking data (credit card codes, passwords, login data) would have been compromised. Nevertheless, the combination of this personal information constitutes prime material for phishing campaigns or large-scale identity theft.

A file put up for sale on the dark web

It was the sale of the customer file on a cybercriminal forum that revealed the extent of the issue. The seller reportedly offered the data of millions of French customers, accompanied by a sample to prove the authenticity of the offer. This type of resale is common in the dark web ecosystem, where stolen databases serve as a real currency of exchange among criminal groups.

Telecom operator data is particularly sought after: it allows for precise targeting of individuals with personalized scams, smishing (SMS phishing), or even preparing more sophisticated attacks like SIM swapping.

Reaction from Free and the authorities

Upon discovering the leak, Free filed a complaint with the Paris prosecutor's office and notified the incident to the CNIL (National Commission on Informatics and Liberty), in accordance with GDPR obligations. The regulatory authority opened a formal investigation to determine the circumstances of the attack and to verify any potential security flaws in the operator's information systems.

Free also began the individual notification of affected customers, advising them to remain particularly vigilant against suspicious solicitations via email, SMS, or phone.

Lasting consequences for customers

Beyond the immediate incident, the consequences of such a leak are felt in the long term. Once published on the dark web, personal data circulates indefinitely, fueling waves of phishing and scam attempts for months or even years.

Cybersecurity experts recommend that affected customers:

  • Increase vigilance against suspicious emails and SMS
  • Activate two-factor authentication (2FA) on all online accounts
  • Monitor their bank statements if their IBAN is among the stolen data
  • Never disclose sensitive information in response to unsolicited calls or messages

A telecom sector particularly targeted

The telecommunications sector remains a prime target for cybercriminals, due to the mass of personal data concentrated with these operators. Free is not the first to suffer: Orange had already experienced a major leak in 2014 (impacting 800,000 customers), and many operators worldwide regularly face this type of attack.

This leak serves as a reminder for companies to harden their defenses and invest in data exfiltration detection, beyond mere perimeter protection. Because once the data is gone, it is too late to retrieve it.


Article written based on information published by national and specialized press in October 2024. See sources below for original publications.