CNIL fines Free/Free Mobile €42M for weak VPN MFA
CNIL fines Free/Free Mobile €42M for weak VPN MFA and failed detection after data exfiltration affecting ~24.6M contracts. Here is the phishing-resistant MFA that would have prevented most of it.
On 13 January 2026, CNIL fined Free Mobile €27M and Free €15M for violations of GDPR Article 32: insufficiently robust VPN authentication and ineffective detection, after an exfiltration affecting ~24.6M contracts. Here is the phishing‑resistant MFA that would have prevented most of it.
The facts
In October 2024, an attacker logged into Free Mobile’s VPN and then pivoted to Free. Between 6 October and detection, data related to 24,633,469 fixed and mobile contracts — including IBANs — was exfiltrated. Following over 2,500 complaints, CNIL found that VPN authentication was “not sufficiently robust” and anomaly detection was ineffective. On 13 January 2026, it imposed a €27M fine on Free Mobile and €15M on Free, also noting shortcomings in data subject information (Art. 34) and, for Free Mobile, in data retention (Art. 5‑1‑e). Official source: CNIL — sanction Free/Free Mobile and decisions SAN‑2026‑001 (Free Mobile) / SAN‑2026‑002 (Free). A press summary is also available: Le Monde.
The applicable legal framework
The fine is primarily based on GDPR Article 32: controllers must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including “the ability to ensure the ongoing confidentiality, integrity, availability,” and mechanisms to “ensure the resilience of systems.” In practice, for large‑scale and sensitive customer data (e.g., IBANs), authorities expect phishing‑resistant strong authentication and monitoring that detects abnormal access. References: Eur‑Lex — GDPR Art. 32, CNIL — Free/Free Mobile.
For entities subject to NIS 2 in Luxembourg, these gaps would also involve Article 21 governance (access controls, monitoring) and the 24‑hour early warning (Art. 23). The ILR highlights this “within 24h” milestone for preliminary notification: ILR — NIS 2 FAQ and ILR — Incident notification.
The technical solution to deploy
Phishing‑resistant MFA (FIDO2/WebAuthn) for VPN/SSO
- What it is: cryptographic, device‑bound and domain‑bound factors (security keys, device‑bound passkeys) that block Adversary‑in‑the‑Middle and reusable OTPs. No codes to type, no interceptable SMS.
- How it works: on enrollment, a public/private key pair is created in the authenticator. At each login, an attestation and a signature bound to the domain/VPN client are verified server‑side. No shared secret transits, making phishing and code harvesting ineffective.
- In VPN/SSO practice: delegate VPN auth to the IdP (OIDC/SAML) with a mandatory FIDO2 policy, disable TOTP/SMS, require a backup FIDO2 factor, and segment admin access with just‑in‑time approval.
- Controls achieved: account‑takeover prevention (ISO 27001 A.5.17), reduced lateral‑movement risk, strong authentication logging (A.8.16), alignment with NIST SP 800‑63B and ENISA good practices.
Minimum complements required under Article 32
- Continuous monitoring: centralized collection of VPN/IdP/EDR logs, anomaly detection (impossible travel, out‑of‑hours access, repeated failures), correlated alerts (ISO 27001 A.8.16). A 24/7 managed SOC orchestrates detections and escalations.
- VPN hardening: client certificate enforcement, strong encryption, dormant account deprovisioning, lockout policies, appropriate geo‑fencing and IP allow‑listing.
- Least privilege: network segmentation, time‑bound admin rights via PAM, automatic revocation at end of engagement (ISO 27001 A.5.15/A.5.18).
- Data minimization/retention: governed retention (GDPR Art. 5‑1‑e) to limit the blast radius of any exfiltration.
How Luxgap delivers this
- Our ISO 27001 governance: workshops on remote‑access use cases, mapping of sensitive flows (including IBANs), target authentication policy, selection of a WebAuthn‑capable IdP, and risk/control matrix (A.5.17, A.8.16). We supply policy templates and regulator‑ready evidence.
- Our 24/7 managed SOC: integration of IdP/VPN/EDR logs, VPN‑specific detection rules (time/IP anomalies, step‑up MFA), escalation runbooks and NIS 2 early warning within 24h in coordination with ILR/CERT‑LU.
- Our outsourced DPO and CISO: legal alignment (GDPR Arts. 32 and 34), CNPD/ILR notification templates, communications plan, and evidence registers (logs, FIDO2 enrollment dashboards, quarterly access reviews).
Real‑world case in Luxembourg or the EU
Example: a business services company subject to NIS 2 and operating in Luxembourg and Belgium migrated remote access to SSO+VPN with mandatory FIDO2 MFA for all privileged accounts, then all staff. In six weeks: guided passkey enrollment (hardware key + mobile passkey), progressive policy cutover, OTP decommissioning. The SOC connected IdP and VPN concentrator logs to correlate failures/“impossible travel” alerts. Result: VPN phishing attempts neutralized, simplified access reviews, and demonstrable 24‑hour notification capability with evidence (meaningful logs, incident timeline, GDPR Art. 34 notices).
Practical first steps
- Decide on the MFA standard: adopt FIDO2/WebAuthn as the default for VPN and IdP, and plan to disable OTP/SMS on external access.
- Map remote access: who connects, to what, and when? List privileged groups and dormant accounts. Clean up before enrollment.
- Run a passkeys pilot: start with IT+Finance+HR, two FIDO2 factors each (hardware key + passkey). Prepare an end‑user onboarding kit.
- Wire the logs: send IdP, VPN, EDR logs to the SIEM. Create early‑warning rules (out‑of‑region connection, multiple failures, long sessions, public TOR/consumer VPNs).
- Prepare notification: GDPR Art. 34‑compliant email templates, NIS 2 sequencing sheet (24h/72h/1 month), and a retention register to reduce exposure.
Official sources
- CNIL — Data breach fine of €42M (Free Mobile/Free)
- CNIL — Decision SAN‑2026‑001 (Free Mobile) and SAN‑2026‑002 (Free)
- Eur‑Lex — GDPR, Article 32 (security of processing)
- ILR — NIS 2: preliminary notification within 24h and ILR — Incident notification
Get in touch to secure your VPN and SSO with phishing‑resistant MFA.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →