A lot of those people might be ex-customers. People who moved, died, or switched to another company. I worked for a mobile company in the US, and once you were in our customer database, you stayed there. We never got hacked, at least, not so far, but if you got access to customer data the total number would be substantially higher than the current customer count.
Like the other reply says, this is not allowed in the EU. You can't just 'stay there'. They must be violating the GDPR if that was the case.
Also their response has been really bad. It was basically them saying "oh well it's not so bad if your details are leaked". And giving some free antivirus crap.