Odido Netherlands Breach Exposes 6.2 Million Customers

The largest telecom breach in Dutch history shows how social engineering can bypass multi-factor authentication to reach centralized customer databases.

Illustration: Odido Netherlands Breach Exposes 6.2 Million Customers
AI-generated illustration · Sylvaris

Phishing Campaign Breached Customer System

Dutch telecommunications provider Odido disclosed on February 12 that hackers accessed its customer contact system during the weekend of February 7-8, 2026, compromising data from approximately 6.2 million customers. The intrusion targeted the CRM platform that consolidates customer records across the company's operations.

The attack involved a multi-stage social engineering campaign. Threat actors first obtained login credentials from customer service employees through targeted phishing emails, then called those same employees while impersonating Odido's internal IT department to manipulate them into approving secondary login requests that bypassed multi-factor authentication protections.

Financial and Identity Data at Risk

The exposed information includes full names, addresses, mobile numbers, email addresses, IBAN bank account details, dates of birth, and passport or driver's license numbers. Internal customer service notes containing account context were also leaked, providing criminals with information that could enable highly convincing targeted fraud.

The ShinyHunters cybercrime group, known for breaches at Ticketmaster and Microsoft, claimed responsibility. They demanded a ransom from Odido, which the company publicly refused on February 26. Following that refusal, the hackers released the dataset to the dark web on March 1.

CRM Systems Under Scrutiny

The Dutch Data Protection Authority is investigating whether Odido violated GDPR data minimization requirements by storing sensitive identification metadata in a customer-facing CRM environment. The breach highlights the risk concentration created when organizations consolidate high-value identity data in single, queryable systems.

Odido notified affected customers and engaged external cybersecurity experts to implement additional security measures. The incident follows similar telecom breaches in South Korea and France, signaling that customer data aggregation platforms have become priority targets for financially motivated threat actors.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.