
Odido Leaks Millions of Customer Data. What Now?
The recent cyberattack on Odido in February 2026, which resulted in personal data of millions of customers falling into the hands of criminals, once again demonstrates the significant impact of… Read more
Explore phishing and social-engineering intelligence and data exposure and breach intelligence in the live cyber intelligence feed.
Explore
Related signal context
Open the classified signal themes connected to this analysis.
The recent cyberattack on Odido in February 2026, which resulted in personal data of millions of customers falling into the hands of criminals, once again demonstrates the significant impact of data breaches at critical service providers. Notably, Odido has communicated transparently and quickly about the incident, its potential consequences, and the measures being taken. This openness helps customers and organizations understand risks in a timely manner and take appropriate actions. At the same time, this situation introduces new threats for companies that rely on telecom services or whose employees are Odido customers.
⚠️ Update: Latest Developments (February 17, 2026)
Since the initial report of the Odido data breach, new details have emerged. Here's what we know now based on the latest reports:
- Scope and Affected Data: Odido has confirmed that data from approximately 6.2 million customers (including its subsidiary brand Ben) has been exfiltrated. This includes names, addresses, dates of birth, IBAN numbers, phone numbers, and in some cases, the numbers and validity dates of identity documents (passport or driver's license). According to Odido, passwords and call history remained secure.
- Cause of Attack: According to sources close to the investigation, hackers gained access to the Salesforce customer environment through social engineering targeting employees. Criminals managed to obtain login credentials and 2FA codes from helpdesk employees, thereby gaining access to the systems.
- Retention Period Exceeded: Research by the Financieel Dagblad reveals that Odido retained data of former customers much longer than its own privacy conditions allow. Data of customers who had left years ago (sometimes up to 10 years after contract termination) are also part of the leak, even though they should have been deleted after two years. The Dutch Data Protection Authority (AP) is investigating this violation.
- Additional Security Measures: Odido has immediately implemented stricter verification rules. For sensitive changes, such as requesting a new SIM card, additional checks are now performed to prevent identity fraud (such as SIM swapping).
- Compensation: Although there are many questions about compensation, Odido maintains that there is (as yet) no direct financial compensation, unless customers have suffered demonstrable financial damage. Legal experts warn that collective claims in the Netherlands are often a lengthy process.
The Consequences for Business Customers
Based on the information shared by Odido itself, the greatest risk lies not in the continuity of service, but in the potential misuse of leaked personal data. Because data such as name, address, contact details, banking information, and in some cases identification data have been exfiltrated, criminals possess strong identity information. With this, they can convincingly impersonate customers, suppliers, or service providers. For organizations, this means an increased risk of targeted social engineering, where attackers try to gain trust through known communication channels such as phone, email, or messaging apps.
How Can This Data Breach Be Misused?
In data breaches of this kind, misuse primarily revolves around identity, trust, and access. Because the leaked data contains strong personal information (contact details, IBAN, possibly ID data), criminals can very credibly impersonate real individuals or organizations. This leads to multiple forms of misuse for businesses.
Identity Fraud
Criminals can impersonate customers, employees, suppliers, or partners. Because they possess real personal data, they can gain trust with helpdesks, support departments, or financial teams. This can lead to unauthorized changes in accounts, contracts, or contact details. For businesses, this means that verification based on standard personal data becomes less reliable.
Targeted Phishing and Social Engineering
With real names and contact details, attackers can send highly convincing messages via email, SMS, WhatsApp, or phone. This can target employees, customers, or business contacts. Instead of general phishing, attacks become personal and contextual, making employees more likely to respond or share information.
Invoice Fraud and Payment Detail Changes
Because bank account numbers and identity information may be known, criminals can attempt to manipulate financial processes. For example, they might request changes to payment details, send fake invoices, or impersonate a supplier or service provider. This primarily affects purchasing and administrative processes and can cause direct financial damage.
Account Takeover and Access Misuse
Personal data is often used for account recovery or identity verification. Attackers can use this information to request password resets, gain access to accounts, or impersonate a legitimate user.
CEO Fraud
With personal data about executives or contacts, attackers can impersonate managers or decision-makers and make urgent financial or operational requests. Because the information appears genuine, employees are more likely to act without additional verification.
Building Extensive Profiles for Future Attacks
Even if data is not immediately misused, it can be combined with other data breaches to create extensive profiles of individuals or organizations. This information can later be used for targeted supply chain attacks, fraud, or espionage.
Advice for Odido Business Customers
For organizations that use Odido or whose employees may be customers, it is wise to treat the incident as an elevated threat period. The telecom service is still operational, but criminals can use the leaked data to exploit trust.
It is advisable to proactively inform employees that a key supplier has been affected by a data breach and that they may be targeted more specifically. Transparent communication prevents uncertainty and increases the likelihood that employees will recognize suspicious situations.
Ask employees to be extra vigilant about unexpected calls, messages, or requests where personal information is used to gain trust. Explain that attackers may impersonate Odido, banks, suppliers, colleagues, or internal departments. Requests concerning payments, account changes, or verification codes, in particular, warrant extra attention.
Additionally, it is advisable to designate a clear internal reporting point where employees can immediately report suspicious communication. An accessible reporting process ensures that alerts become visible quickly and prevents incidents from going unnoticed.
It also helps to temporarily place extra emphasis on verification procedures. Employees should know that it is always permissible to verify requests through a second channel or to ask for additional confirmation, especially for financial or account-related actions.
Finally, it is important to emphasize the human element: employees do not need to be security experts, but their vigilance can make all the difference.
Conclusion
The way Odido communicates the incident deserves recognition. By quickly providing clarity about the nature of the breach and the potential risks, the company enables customers and partners to take timely measures. At the same time, this incident shows that cyberattacks are rarely limited to a single organization. In a highly connected digital economy, incidents at one party can ripple through the entire chain. For businesses, it is therefore essential not only to monitor their own security but also the risks arising from suppliers and service providers on whom they depend.
For organizations looking to strengthen their digital resilience, this means that continuous monitoring of suppliers and their cyber incidents is becoming increasingly important. Insight into incidents at critical parties helps companies to identify risks more quickly and take proactive measures before damage occurs. Precisely in incidents like this, the importance of supply chain visibility for effective risk management becomes clear.