CNIL Alerts Surge in Large-Scale Data Violations
- PARIS (AP) — France's data protection authority, teh CNIL, reported a notable increase in personal data breaches, with 5,629 violations notified in 2024, a 20% rise from the...
- The number of breaches impacting more than one million people doubled in a year, climbing from approximately twenty to forty accomplished attacks.The CNIL notes this accelerated trend has...
- According to the CNIL, common attack methods involve compromised connection information, undetected intrusions and data exfiltration before datasets are sold, and vulnerabilities within subcontractors.
CNIL Reports Surge in Personal Data Violations; Large-Scale Breaches Double
Table of Contents
- CNIL Reports Surge in Personal Data Violations; Large-Scale Breaches Double
- CNIL Reports: Your Questions Answered About the Surge in Data Breaches
- What is the CNIL and what did it report?
- How many data breaches were reported in 2024?
- How does this compare to the previous year?
- What’s particularly concerning about the trend?
- What’s the definition of a “large-scale violation” according to the CNIL?
- How has the number of large-scale breaches changed?
- What sectors are affected by these breaches?
- Which organizations were specifically mentioned as being victims of data breaches in 2024?
- What are the most common methods used in these cyber attacks?
- Who is Marie-Laure Denis, and what did she say about the situation?
- What percentage of the breaches resulted from cyberattacks vs. internal human errors?
- How is the CNIL responding to this surge in data breaches?
- What is the CNIL planning to implement to improve data security?
- What is double authentication?
- When will double authentication be mandated?
- Who will be required to use double authentication?
- What does the CNIL believe that double authentication, access monitoring tools and employee training will achieve?
- What is the CNIL’s strategic plan focused on?
- What security measures does the CNIL recommend?
- what are the key threats and solutions highlighted by the CNIL?
PARIS (AP) — France’s data protection authority, teh CNIL, reported a notable increase in personal data breaches, with 5,629 violations notified in 2024, a 20% rise from the previous year. The agency highlighted a particularly concerning trend: a surge in large-scale violations affecting over a million individuals.
The number of breaches impacting more than one million people doubled in a year, climbing from approximately twenty to forty accomplished attacks.The CNIL notes this accelerated trend has continued into the first quarter of 2025. All sectors, both private and public, are affected, citing France Travail, Free, Auchan, Truffaut, Cultura, and Boulanger as examples of organizations targeted in 2024.
According to the CNIL, common attack methods involve compromised connection information, undetected intrusions and data exfiltration before datasets are sold, and vulnerabilities within subcontractors.
CNIL President Marie-Laure Denis stated that major databases “are not protected enough,” describing the situation as “failures.” She emphasized that ”the question is not whether there will be a cyber attack but when.” Denis also pointed to telework vulnerabilities that have not been fully addressed as the pandemic, particularly regarding remote access security.
Of the notified violations, 55% resulted from cyberattacks such as ransomware and phishing, while 20% stemmed from internal human errors.
CNIL to Require Double Authentication
To combat this growing threat, the CNIL will issue a recommendation this week mandating double authentication by 2026. This measure will require employees, partners, and subcontractors remotely accessing large databases of several million people to provide an additional identity verification factor beyond a password.
The CNIL believes that this measure, combined with access monitoring tools and employee awareness training, could have prevented 80% of the large-scale data breaches it observed.
Cybersecurity as a Strategic priority
The CNIL has made cybersecurity a central focus of its 2025-2028 strategic plan. The commission emphasizes the need for organizations to adopt risk-appropriate security measures.
Recommendations include:
- Promptly installing updates to address security vulnerabilities.
- Using strong, unique passwords for each account.
- Conducting regular user awareness training.
- Protecting access to messaging systems to prevent them from becoming attack entry points.
- Performing regular data backups.
CNIL Reports: Your Questions Answered About the Surge in Data Breaches
This article provides answers to common questions about the recent report from France’s data protection authority, the CNIL, regarding the increase in data breaches.
What is the CNIL and what did it report?
The CNIL (Commission Nationale de l’Informatique et des Libertés) is France’s data protection authority. In its 2024 report, the CNIL noted a significant rise in personal data breaches.
How many data breaches were reported in 2024?
the CNIL reported 5,629 data violations in 2024.
How does this compare to the previous year?
The 2024 figure represents a 20% increase in data breach notifications compared to the previous year.
What’s particularly concerning about the trend?
The CNIL highlighted a troubling increase in “large-scale violations” – breaches affecting over a million individuals.
What’s the definition of a “large-scale violation” according to the CNIL?
A large-scale violation, as used in the CNIL’s report, refers to a data breach impacting over a million people.
How has the number of large-scale breaches changed?
The number of breaches impacting over a million people doubled in a year, climbing from approximately twenty to forty.
What sectors are affected by these breaches?
All sectors are affected, both private and public.
Which organizations were specifically mentioned as being victims of data breaches in 2024?
The CNIL cited France Travail, Free, Auchan, Truffaut, Cultura, and Boulanger as examples of organizations targeted in 2024.
What are the most common methods used in these cyber attacks?
According to the CNIL, the common attack methods include:
Compromised connection facts (e.g., stolen or weak passwords)
Undetected intrusions and data exfiltration (data being stolen without the association’s knowledge)
Vulnerabilities within subcontractors (security weaknesses thru third-party vendors)
Who is Marie-Laure Denis, and what did she say about the situation?
Marie-Laure Denis is the President of the CNIL.she stated that major databases “are not protected enough,” describing the situation as “failures.” She also emphasized that “the question is not whether there will be a cyber attack but when.”
What percentage of the breaches resulted from cyberattacks vs. internal human errors?
Of the notified violations:
55% resulted from cyberattacks (like ransomware and phishing).
20% stemmed from internal human errors.
How is the CNIL responding to this surge in data breaches?
The CNIL is implementing several measures and recommendations to combat the growing threat.
What is the CNIL planning to implement to improve data security?
The CNIL will be issuing a recommendation regarding double authentication.
What is double authentication?
Double authentication, also known as two-factor authentication (2FA), requires users to provide an additional identity verification factor (beyond a password) when accessing sensitive data remotely.
When will double authentication be mandated?
The CNIL will be mandating double authentication by 2026.
Who will be required to use double authentication?
Employees, partners, and subcontractors remotely accessing large databases of several million people.
What does the CNIL believe that double authentication, access monitoring tools and employee training will achieve?
The CNIL believes that these three things might have prevented 80% of the breaches it observed.
What is the CNIL’s strategic plan focused on?
Cybersecurity is a central focus of the CNIL’s 2025-2028 strategic plan. The commission emphasizes the need for organizations to adopt risk-appropriate security measures.
What security measures does the CNIL recommend?
The CNIL’s recommendations include:
Promptly installing updates to address security vulnerabilities.
Using strong,unique passwords for each account.
Conducting regular user awareness training.
protecting access to messaging systems to prevent them from becoming attack entry points.
performing regular data backups.
what are the key threats and solutions highlighted by the CNIL?
| Threat | Description | Recommended Solution |
| ————————– | —————————————————————————————————————————— | ————————————————————————————- |
| data Breach Surge | Increase in the number and impact of data breaches | Double authentication, access monitoring tools, employee training, all related to 2026. |
| Compromised Credentials | Attacks gaining access through stolen or weak passwords. | Strong passwords, regular updates |
| Insider Error | Errors that happen inside an organisation | security protocol training |
| System vulnerabilities | exploited by attackers. | Install security updates promptly. |
| Lack of Awareness | Employees not understanding security threats or best practices which is a key reason for attacks. | Regular user awareness training. |
| Telework vulnerabilities | Security weaknesses related to remote work setup and access. | The specific solution is not mentioned here but Denis does call it out. |
