October 28, 2024 at 01:49PM
French ISP Free confirmed a data breach affecting 19.2 million customers, with personal information, including 5.11 million IBAN numbers, stolen. The company has filed a criminal complaint and notified authorities. Although no passwords or bank card details were accessed, impacted subscribers are being informed and advised to monitor for unusual activity.
**Meeting Takeaways: Free ISP Data Breach Incident**
1. **Incident Overview:**
– Free, a leading internet service provider in France, experienced a significant data breach involving customer personal information.
– The incident, confirmed over the weekend, affects approximately 19.2 million customers, representing nearly a third of the French population.
2. **Company Profile:**
– Free is the second-largest telecommunications company in France, with over 22.9 million subscribers and is part of the Iliad Group.
3. **Actions Taken:**
– Free has filed a criminal complaint with the public prosecutor.
– The company notified the French National Commission for Information Technology and Civil Liberties (CNIL) and the National Agency for the Security of Information Systems (ANSSI).
– Affected subscribers are being informed via email.
4. **Data Specifics:**
– Data exposed in the breach includes over 5.11 million IBAN numbers.
– However, customer passwords, bank card details, and the content of communications (emails, SMS, voice messages) were not accessed.
5. **Data Auction:**
– The stolen data is being auctioned on BreachForums by a threat actor known as “drussellx.”
– Evidence of the breach, including screenshots and database headers, has been provided for legitimacy.
6. **Customer Guidance:**
– Free has advised subscribers to monitor for unusual direct debits, which banks are obliged to reimburse if reported within 13 months.
– Subscribers are cautioned against phishing attempts, specifically against sharing access codes or bank information through email, SMS, or calls.
7. **Further Information Pending:**
– Additional details about the detection of the breach and the total number of impacted customers are awaited from Free’s spokesperson.
This summary encapsulates the key points discussed regarding the recent data breach affecting Free and provides actionable insights for stakeholders involved.