Free, France’s second-largest telecoms company, confirms being hit by cyberattack

Avatar

Free, the second-largest internet service provider in France, confirmed being hacked this weekend following the attempted sale of purportedly stolen customer information on a cybercrime forum.

The Paris-based company has issued a warning that personal data was compromised in the incident, has filed a criminal complaint with the country’s public prosecutor and has notified France’s cybersecurity agency, as reported by newspaper Le Monde on Saturday.

The nature of the cyberattack has not been confirmed. The company said the intruders targeted an internal management tool and that the unauthorized access involved “personal data associated with the accounts of certain subscribers.”

“The affected subscribers have been or will be informed by email shortly,” said the company, adding that passwords and bank card details were unaffected, as were the contents of any of its users’ communications.

Free has not confirmed the total number of individuals impacted by the breach, not when it took place.

The company’s acknowledgement of the incident followed a cybercriminal listing what they claimed were two databases stolen from Free, affecting more than 19 million customers, on a cybercrime forum.

“All necessary measures have been taken immediately to put an end to this attack and strengthen the protection of our information systems,” stated Free.

The incident follows another attack in September impacting SFR, another telecommunications operator in France, when a tool for managing customer orders was compromised.

IndustryNewsCybercrimeNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.

 

Total
0
Shares
Previous Post

Dozens under investigation in Italy amid scandal over hacked government databases and illegal dossiers

Next Post

‘All servers’ for Redline and Meta infostealers hacked by Dutch police and FBI

Related Posts

Nation-State Attackers Exploiting Ivanti CSA Flaws for Network Infiltration

A suspected nation-state adversary has been observed weaponizing three security flaws in Ivanti Cloud Service Appliance (CSA) a zero-day to perform a series of malicious actions. That's according to findings from Fortinet FortiGuard Labs, which said the vulnerabilities were abused to gain unauthenticated access to the CSA, enumerate users configured in the appliance, and attempt to access the
Avatar
Read More

CISA Flags Critical Flaws in Mitel and Oracle Systems Amid Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three flaws impacting Mitel MiCollab and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is as follows - CVE-2024-41713 (CVSS score: 9.1) - A path traversal vulnerability in Mitel MiCollab that could allow an attacker
Avatar
Read More

Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans

Russian-speaking users have become the target of a new phishing campaign that leverages an open-source phishing toolkit called Gophish to deliver DarkCrystal RAT (aka DCRat) and a previously undocumented remote access trojan dubbed PowerRAT. "The campaign involves modular infection chains that are either Maldoc or HTML-based infections and require the victim's intervention to trigger the
Avatar
Read More