Free Data Breach (2024): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Free Data Breach (2024) was disclosed on 17 October 2024, exposing the names, dates of birth, genders, phone numbers, and bank account numbers of 13.9 million people. Individuals should verify whether their information was included and take steps to protect their accounts.
Large-scale compromises of customer databases at telecommunications and internet service providers have become a recurring feature of the current threat landscape, where stolen personal and financial records are routinely offered for sale and then dumped into public view. Against that backdrop, a data breach affecting Free, a major French internet service provider, was reported on 17 October 2024. Roughly 13.9 million people were drawn into the incident when records containing personal identifiers and bank-account details were posted for sale and later leaked publicly. The episode matters because the volume and sensitivity of the material create lasting opportunities for fraud, social engineering and identity misuse long after the initial disclosure.
What happened
In October 2024 Free suffered a data breach. The compromised material was subsequently posted for sale and later leaked publicly. Reporting dated 17 October 2024 indicated that approximately 13.9 million people were affected. The data set contained around 14 million unique email addresses together with names, physical addresses, phone numbers, genders, dates of birth and, for many records, IBAN bank-account numbers. Free publicly advised that the bank-account numbers alone were “not enough to make a direct debit from a bank.” No further technical details about the intrusion method, exact timing of the initial compromise, or the full chain of custody of the data have been disclosed in the available record.
How a breach like this happens
Incidents of this type typically begin when an attacker gains unauthorised access to systems that store customer records. Common entry points include exploitation of unpatched software vulnerabilities, credential-stuffing attacks that reuse passwords stolen elsewhere, phishing campaigns that trick staff into revealing access tokens, or misconfigured cloud storage that leaves databases exposed to the open internet. Once inside, the attacker often moves laterally, locates large repositories of personal data, and extracts them for later sale or public release. The subsequent appearance of the data on underground markets or leak sites is a frequent final stage; buyers or opportunistic actors then redistribute the material more widely. No specific threat group has been attributed to the Free incident, and the precise technique used here remains undisclosed.
Free and its sector
Free is a French internet service provider that supplies broadband, mobile and related connectivity services to a large domestic customer base. Organisations in this sector routinely collect and retain extensive personal information required for account creation, billing, network provisioning and customer support. That information commonly includes contact details, service addresses, payment identifiers and demographic data. Because these companies sit at the centre of everyday digital life, a breach of their customer databases is consequential: the same records that enable legitimate service delivery can also be weaponised for targeted fraud, SIM-swap attempts or large-scale phishing campaigns that exploit the trust customers place in their provider.
The information in question
The records associated with this breach have been described as containing the following categories of data:
- Bank account numbers (IBANs for many records)
- Dates of birth
- Genders
- Names
- Phone numbers
- Physical addresses
Approximately 14 million unique email addresses were also present. Free stated that the bank-account numbers were insufficient on their own to initiate a direct debit. Beyond these named fields, the exact contents of every record remain unconfirmed in public reporting; organisations of this kind typically hold additional service and billing metadata, but no such further details have been verified for this incident.
Why it matters
For affected individuals the combination of name, address, date of birth, phone number and email address supplies the raw material for identity fraud, account takeovers and highly convincing social-engineering attacks. Even partial bank-account details can be used to craft more credible payment-related scams or to attempt unauthorised transactions once additional verification data is obtained elsewhere. Free’s own clarification that the IBANs alone could not trigger direct debits reduces one immediate risk, yet it does not eliminate the longer-term value of the data set to criminals who specialise in multi-stage fraud. For the organisation the breach carries operational, regulatory and reputational consequences, including the need to notify regulators and customers, strengthen controls, and manage the secondary effects of public data circulation. Because the material has already been offered for sale and leaked, the exposure is effectively permanent; affected people may continue to encounter misuse attempts years after the original event.
Were you affected?
If you are or have been a Free customer, treat the possibility of exposure as real. Practical first steps include reviewing bank and credit statements for unfamiliar activity, enabling multi-factor authentication on email and financial accounts, and remaining alert to unexpected calls or messages that reference personal details. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Where local law provides credit-monitoring or fraud-alert services, consider activating them. Public detail on individual notification remains limited, so proactive personal vigilance is the most reliable immediate defence.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Speedio Data Breach (2024)Young Living Essential Oils Data Breach (2024)Senior Dating Data Breach (2024)FlipaClip Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the Free Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.