Odido
Incident posture
Timeline
Summary
Odido disclosed a breach affecting approximately 6.2 million customers, including users of its MVNO Ben NL. Compromised data included names, addresses, phone numbers, email addresses, dates of birth, customer numbers, bank account numbers, and passport or driver’s license details; passwords, call records, and billing information were not accessed. The intrusion ended after detection, and the operator reported the incident to authorities, launched an investigation, and engaged cybersecurity experts to strengthen defenses. Investigators indicated the attackers used social engineering, sending phishing emails to customer service staff and then posing as the IT department by phone to trick employees into approving fraudulent logins. No extortion group has claimed responsibility for the attack.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 7‑8 2026, unauthorized access occurred to Odido’s customer contact system, as disclosed by the company in a notice dated February 13. The breach was reported earlier in the month, with Odido informing customers on February 16 that their personal data may have been leaked. Approximately 6.2 million customers, including both direct Odido subscribers and users of its mobile virtual network operator Ben NL, were affected. The compromised data included names, addresses, phone numbers, email addresses, dates of birth, customer numbers, bank account numbers, and passport or driver’s license numbers and validity. Odido stated that no passwords, call records, or invoice data were accessed during the incident. According to Odido’s statement and reporting from Dutch public broadcaster NOS, the attackers gained entry by first obtaining credentials of customer service representatives who had fallen for phishing emails, then contacting those employees by phone while posing as the IT department to manipulate them into approving a fraudulent login attempt. The targeted staff may have been external call centre workers based outside the Netherlands.
Upon discovering the breach, Odido immediately closed the attackers’ access to its systems and reported the incident to the Dutch Data Protection Authority. The company brought in cybersecurity experts to conduct an ongoing investigation and to implement additional security measures. Odido notified the affected users directly via email or phone, urging them to be wary of suspicious and unusual activities such as phishing calls or texts. The operator emphasized that its services had not been impacted by the breach and that no call records or billing data had been compromised. Odido also stated that it was not aware of the stolen information being published online, but that it continued to monitor the web in collaboration with cybersecurity experts and could not rule out that the leaked data might be misused or published at a later time. No known extortion group has claimed responsibility for the attack, and Odido has not disclosed further details about the threat actor.
Sources
Sources available to members: 2 sources.