Free, France’s second-largest telecoms company, confirms being hit by cyberattack

Avatar

Free, the second-largest internet service provider in France, confirmed being hacked this weekend following the attempted sale of purportedly stolen customer information on a cybercrime forum.

The Paris-based company has issued a warning that personal data was compromised in the incident, has filed a criminal complaint with the country’s public prosecutor and has notified France’s cybersecurity agency, as reported by newspaper Le Monde on Saturday.

The nature of the cyberattack has not been confirmed. The company said the intruders targeted an internal management tool and that the unauthorized access involved “personal data associated with the accounts of certain subscribers.”

“The affected subscribers have been or will be informed by email shortly,” said the company, adding that passwords and bank card details were unaffected, as were the contents of any of its users’ communications.

Free has not confirmed the total number of individuals impacted by the breach, not when it took place.

The company’s acknowledgement of the incident followed a cybercriminal listing what they claimed were two databases stolen from Free, affecting more than 19 million customers, on a cybercrime forum.

“All necessary measures have been taken immediately to put an end to this attack and strengthen the protection of our information systems,” stated Free.

The incident follows another attack in September impacting SFR, another telecommunications operator in France, when a tool for managing customer orders was compromised.

IndustryNewsCybercrimeNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.

 

Total
0
Shares
Previous Post

Dozens under investigation in Italy amid scandal over hacked government databases and illegal dossiers

Next Post

‘All servers’ for Redline and Meta infostealers hacked by Dutch police and FBI

Related Posts

5,000 Phishing PDFs on 260 Domains Distribute Lumma Stealer via Fake CAPTCHAs

Cybersecurity researchers have uncovered a widespread phishing campaign that uses fake CAPTCHA images shared via PDF documents hosted on Webflow's content delivery network (CDN) to deliver the Lumma stealer malware. Netskope Threat Labs said it discovered 260 unique domains hosting 5,000 phishing PDF files that redirect victims to malicious websites. "The attacker uses SEO to trick victims into
Avatar
Read More

Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts

Cybersecurity researchers have discovered several cryptocurrency packages on the npm registry that have been hijacked to siphon sensitive information such as environment variables from compromised systems. "Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers," Sonatype researcher Ax Sharma said. "However, [...] the latest
Avatar
Read More