Breach report
TelecomOdido
Dutch Carrier Odido Discloses Data Breach Impacting 6 Million
Attackers who tricked Odido staff into approving login requests stole data on about 6.2 million Dutch telecom customers, including bank account and ID numbers, then published it all when the carrier refused to pay.
Reported by SecurityWeek
Records exposed
6.2M
About 6.2 million customers
Scale vs. largest on file
- When
- 2026
- How they got in
- Phishing and MFA-fatigue social engineering leading to Salesforce data theft
- Sector
- Telecom
In February 2026, Odido, the Dutch mobile and broadband provider formerly known as T-Mobile Netherlands, disclosed that attackers had stolen personal data belonging to more than 6 million current and former customers of Odido and its budget brand Ben. The company said the unauthorized access occurred on February 7 and 8, that it had cut off the intruders and that it had notified the Dutch Data Protection Authority. A company representative put the number of affected people at about 6.2 million.
According to later reporting, the attackers combined phishing and phone-based impersonation. They obtained employee passwords, then called the same staff while posing as IT support and persuaded them to approve multi-factor authentication prompts. That access led to Odido's Salesforce customer management environment, where the intruders used automated tools to extract records in bulk. The extortion group ShinyHunters, linked to a series of similar Salesforce-focused attacks, claimed responsibility later in the month.
The stolen information included names, addresses, phone numbers, email addresses, dates of birth and customer numbers, as well as IBAN bank account numbers and passport or driver's license numbers with their validity dates. Odido said no passwords, call records or invoice data were affected. Reporting also indicated that internal customer service notes were exposed, some describing sensitive personal circumstances, which heightened concern about targeted scams and harm to vulnerable customers.
ShinyHunters demanded a ransom reportedly worth several million euros. Odido refused to negotiate, and beginning on February 26 the group published the data in escalating batches, first releasing hundreds of thousands of customer and business records, then bank details and scans or numbers of identity documents. By March 1, the group said it had released the full dataset covering about 6.5 million people and 600,000 businesses. The Dutch Public Prosecution Service opened a criminal investigation, and scammers quickly set up a fake class-action website charging victims a fee to register claims.
The Odido breach is one of the largest in Dutch history and a prominent 2026 example of help-desk and MFA-approval social engineering. It showed that push-based multi-factor authentication can be defeated when employees are manipulated into approving requests, and it added to pressure on companies to adopt phishing-resistant methods and restrict bulk exports from cloud CRM platforms.