Odido 2026 Data Breach

Odido Dutch Telecom Breach (2026): 6.2 Million Customer Records Including Bank Account, Passport, Driver's License & Government ID Exposed

Company · Telecommunications services · Mobile and broadband provider · Netherlands

Odido Dutch Telecom Breach (2026): 6.2 Million Customer Records Including Bank Account, Passport, Driver's License & Government ID Exposed

Dutch telecommunications provider for mobile, broadband, and TV services.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
100/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
6.2MRecords
2026Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
Gov IDDriver’s License; Government ID; Passport Number
FinancialBank Account Number
AddressPhysical address
Classification Tags
ShinyHuntersSocial EngineeringTelecommunicationsDirect Customers2026

Breach Summary

In mid-February 2026, attackers compromised Odido's customer-management (CRM) system after phishing customer-service employees for their credentials and defeating multi-factor authentication through voice-based social engineering, then used automated scripts to exfiltrate data on approximately 6.2 million current and former customers. Exposed fields reportedly included names, addresses, phone numbers, email addresses, dates of birth, customer numbers, bank account (IBAN) numbers, and passport, driver's license and national ID numbers. After Odido declined a roughly EUR 1 million ransom, the threat actor ShinyHunters released the dataset in stages beginning around March 1, 2026 across dark-web forums including BreachForums. The breach is cataloged by Have I Been Pwned and DataBreach.com and confirmed by Odido.

Full threat analysis, exploitation vectors, and principal guidance below.

12 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

6.2M records analyzed

About Odido

Odido is the largest telecommunications operator in the Netherlands, providing mobile, broadband, and TV services to consumer and business subscribers. It was formed in 2023 when T-Mobile Netherlands and Tele2 Netherlands were merged and rebranded as Odido under owners Apax Partners and Warburg Pincus. As a national carrier it runs retail, billing, and customer-management systems supporting millions of active accounts across the country.

Why They Hold Your Data

Telecommunications providers collect subscriber identity, phone numbers, billing records, service addresses, device data, and account-management information across mobile and broadband services.

Recent Developments

Odido continues to operate as the Netherlands' largest mobile network. After the February 2026 compromise of its customer-management system it disclosed the incident publicly, published a customer FAQ, and declined to pay the attackers' ransom demand. The breach has drawn regulatory scrutiny under Dutch data-protection authorities and prompted at least one class-action claim on behalf of affected customers.

Data Points Exposed

11 verified field types
Bank Account Number Critical
Customer Service Records
Date of Birth High
Driver’s License Critical
Email Address
Full Name
Gender
Government ID Critical
Passport Number Critical
Phone Number
Physical address High

Breach Impact

The breach exposed a highly sensitive combination of identity, contact, and financial identifiers for roughly 6.2 million current and former customers, including bank account (IBAN) numbers and government-issued ID numbers. For a national carrier, exposure at this scale creates lasting account-security and fraud risk for a large share of the Dutch population, erodes subscriber trust, and carries significant regulatory and reputational consequences given the volume and sensitivity of the data and the public extortion and leak that followed.

Exploitation & Downstream Threats

• Financial fraud and unauthorized transfers using exposed bank account (IBAN) numbers | • Identity theft and synthetic identity construction using passport, driver's license and government ID numbers | • Identity verification bypass using name, date of birth and ID number combinations | • SIM swap and account-takeover attacks leveraging exposed phone numbers | • Targeted phishing and vishing impersonating Odido using exposed contact and customer-service data | • Doxxing and physical targeting from exposed home addresses

Principal Risk Advisory

What this means for a principal

A telecom breach: subscriber and device data supports SIM-swap, account takeover and location inference. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
S
Threat Actor: ShinyHuntersConfidence: High
Data theft / extortion group

Motivation: Financial extortion, data sale
A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.

Read the full threat-actor profile →
This breach is linked to the ShinyHunters / Scattered Lapsus$ Hunters - Salesforce (2025-26) campaign. See the full campaign analysis →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation