Optimove A.I CyberSecurity Scoring
Optimove
Company Information
Website:https://www.optimove.com
Employees number:591
Number of followers:31,122
NAICS:5112
Industry Type:Software Development
Homepage:optimove.com
Optimove Risk Score (AI oriented)
Between 550 and 599
OptimoveSoftware Development
Updated:
04/04/2026
04/04/2026
584/1000
Very Poor
Ca
Optimove Global Score (TPRM)
xxxx
OptimoveSoftware Development
Score locked

OptimoveVery Poor
Current Score
584Ca (VERY POOR)
01000
1 incidents
-185 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
598
JULY 2026
596
JUNE 2026
593
MAY 2026
589
APRIL 2026
587
MARCH 2026
583
FEBRUARY 2026
578
JANUARY 2026
577
DECEMBER 2025
756
Breach
11 Dec 2025 • Optimove
Deezer and Optimove: French regulator fines Israeli marketing platform €1M for processor violations
CNIL Imposes €1 Million Fine on Optimove for GDPR Violations Leading to Deezer Data Breach
571
CRITICAL-185
DEEOPT1766231704
CNIL Fines Israeli Marketing Firm Optimove €1M for GDPR Violations in Massive Deezer Data Breach
France’s data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), imposed a €1 million fine on Israeli marketing technology company Optimove (operating as Mobius Solutions Ltd.) on December 11, 2025, for systematic failures in GDPR compliance that led to a data breach affecting 46.9 million Deezer users worldwide, including 9.8 million in France.
### Key Violations and Findings
The enforcement action targeted three GDPR violations:
1. Article 28(3)(g) – Failure to delete or return personal data after the contract with Deezer ended (December 1, 2020). Optimove retained non-anonymized user data in a non-production environment until October 1, 2023, nearly a year after Deezer reported the breach.
2. Article 29 – Processing personal data without controller instructions. Optimove copied data from 9.8 million French Deezer users to an unauthorized environment for internal use, despite contractual prohibitions.
3. Article 30 – Lack of a formal register of processing activities, a requirement for processors handling high-risk data, even for companies with fewer than 250 employees.
The breach exposed sensitive user data, including identifiers, contact details, listening habits, payment information, and behavioral profiles, which later surfaced on the darknet, increasing risks of phishing and identity theft.
### How the Breach Unfolded
- April 2019: Optimove employees copied non-anonymized Deezer user data from a production environment to an unauthorized non-production system.
- December 1, 2020: The contract with Deezer ended, but Optimove failed to delete the data as required.
- October 31–November 5, 2022: The breach occurred, exposing 46.9 million users globally.
- November 10, 2022: Deezer notified CNIL, identifying Optimove as the likely source.
- January 31, 2023: Deezer confirmed the breach originated from Optimove’s systems.
- October 1, 2023: Optimove finally deleted the unauthorized data copy—nearly a year after the breach was reported.
### Legal and Regulatory Impact
The case marks a significant enforcement action against a non-EU data processor, reinforcing that GDPR applies to companies monitoring behavior of EU individuals (Article 3(2)(b)), even if based outside the bloc. The CNIL rejected Optimove’s arguments that:
- Employee actions without management knowledge excused the violations.
- International comity (Israel’s adequacy status) should limit CNIL’s jurisdiction.
- Behavioral profiling did not fall under GDPR’s territorial scope.
The decision aligns with broader EU regulatory trends, where data processors face direct liability for compliance failures. Recent cases, such as McDonald’s Poland’s €3.89M fine (July 2025) and Germany’s standardized fine procedures (June 2025), underscore heightened scrutiny on processor accountability.
### Penalty Calculation and Next Steps
The €1 million fine—below the 2% of global revenue cap—reflects CNIL’s consideration of Optimove’s financial situation (reported revenues of $30–40M in 2023–2024) and cooperation level, though the company initially contested responsibility. The decision will be publicly published for two years before anonymization.
Optimove has four months to appeal to France’s Council of State but has not indicated whether it will challenge the ruling. The case serves as a precedent for marketing technology providers, emphasizing that processors must implement strict controls over data handling, deletion, and employee activities to avoid GDPR violations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
756
OCTOBER 2025
756
SEPTEMBER 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Optimove ??
What was Optimove's A.I Rankiteo Cyber Score in July 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in June 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in May 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in April 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in March 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in February 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in January 2026 ??
What was Optimove's A.I Rankiteo Cyber Score in December 2025 ??
What was Optimove's A.I Rankiteo Cyber Score in November 2025 ??
What was Optimove's A.I Rankiteo Cyber Score in October 2025 ??
What was Optimove's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Optimove's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Optimove ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Optimove's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?