France Published Four Breach Fines in One Day (08/21/2026)
- › France's data protection authority published four breach decisions, totalling nearly 50 million euros.
- › Free Mobile was fined 27 million euros and Free 15 million over an October 2024 breach touching 24 million subscriber contracts, including bank account numbers.
- › The CNIL cited weak virtual private network authentication, ineffective anomaly detection, and notification emails that left people unable to understand the consequences.
- › France Travail was fined 5 million euros, Nexpublica France 1.7 million, and Mobius Solutions 1 million.
- › Civil society groups are calling on Nottinghamshire Police to halt live facial recognition.
Four breach decisions published in a day, adding up to nearly 50 million euros. Read them together and the interesting part is what the regulator kept finding: not exotic attacks, but authentication that was too weak on a remote access path, monitoring that did not notice, and notification letters that technically went out and told people nothing usable.
Top 5 Critical Privacy Alerts
1. Free Mobile and Free Fined 42 Million Euros
Attackers reached the systems of Free Mobile and Free in October 2024 and accessed personal data for 24 million subscriber contracts, including bank account numbers for people who were customers of both. More than 2,500 formal complaints followed. The CNIL found three failures: inadequate authentication on the virtual private network and ineffective detection of abnormal behaviour, notification emails that lacked the information people needed to understand the consequences and protect themselves, and, for Free Mobile alone, a failure to delete data belonging to former subscribers. Free Mobile was fined 27 million euros and Free 15 million. EDPB
Operator Note: Two of the three findings are about what happened after the intrusion. The regulator penalised the notification itself for being technically compliant and practically useless, which is a standard most breach letters would fail. Go read your own template now, as a customer would, and ask whether it tells that person what specifically was taken about them and what to do today.
2. France Travail Fined 5 Million Euros
The French employment agency was fined 5 million euros over a data breach. EDPB
Operator Note: A public employment service holds the record of who is out of work and looking, which is one of the categories people most want kept quiet. Nobody chooses to give that data to a government agency, and that absence of choice is exactly why the retention and access questions around it deserve more scrutiny than a commercial dataset would get.
3. Nexpublica France Fined 1.7 Million Euros
Nexpublica France was fined 1.7 million euros following a data breach. EDPB
4. Mobius Solutions Fined 1 Million Euros
Mobius Solutions Ltd was fined 1 million euros over a breach. EDPB
Operator Note: Look at the range in one day: 42 million at the top and 1 million at the bottom. The mid-sized companies in that list are the useful signal for most readers, because a seven-figure penalty is survivable for a telecom and existential for a firm of a few hundred people holding the same category of data.
5. Civil Society Asks Nottinghamshire Police to Stop Live Facial Recognition
The Electronic Frontier Foundation and other groups are calling on Nottinghamshire Police to halt live facial recognition deployment. Live recognition scans everyone who walks past rather than checking a specific person against a specific warrant. EFF
Operator Note: The distinction between live and retrospective recognition is the one that keeps getting lost in coverage, and it is the whole argument. Retrospective matching starts with an investigation and asks about one person. Live matching starts with a street and asks about everyone on it, then discards the answers it does not want, which is a search that happened whether or not anything came of it.
Additional Privacy Alerts
Privacy Laws & Regulations
- Connecticut’s omnibus AI law is a useful window into where state regulation is heading: The trending issues it surfaces are the ones other states are drafting toward. Sidley Data Matters
- The Dutch data protection agency is advising Twitch users to opt out of data sharing with Amazon: A regulator giving direct instructions to users rather than to the company. PogoWasRight
Privacy-Enhancing Technologies
- NIST selected 11 contactless fingerprint providers for certification testing: Contactless capture removes the surface everyone touches and keeps everything else about fingerprinting intact. Biometric Update
- Eye tracking is entering the age assurance market: Another biometric proposed as the gentle way to check a birthday. Biometric Update
Cross-Border Data Transfers
- Brazil’s sovereign identity strategy rests on a 376 million record biometric database: Biometric Update
- Gulf states have a digital identity boom sitting on a fragmented verification landscape: Adoption is running ahead of interoperability, which usually resolves by one vendor becoming the standard. Biometric Update
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.