Dutch mobile phone giant Odido announces data breach

The largest mobile phone provider in the Netherlands announced a cyberattack on Thursday that led to the theft of customer information. 

The company Odido, told a local news outlet that 6.2 million people had information stolen. In a statement about the incident, Odido CEO Søren Abildgaard said names, bank account numbers, addresses, mobile numbers, email addresses, account numbers and IDs – ranging from passports to driver’s license numbers – were stolen by the hackers. 

Abildgaard said the incident took place on February 7 and was eventually reported to the Dutch Data Protection Authority once the breach was confirmed. 

Investigators traced the attack back to a compromised customer contact system used by Odido. The cybercriminals downloaded customer information after gaining access. 

The company’s operations have not been impacted by the attack and the unauthorized access “was terminated as quickly as possible.”

No cybercriminals have come forward to claim the attack. Customers will be contacted directly by Odido if they are impacted. 

The statement includes several scenarios outlining how cybercriminals could use the information they stole. They warned victims that hackers could contact victims posing as Odido officials and use the information to verify their legitimacy. Some may send phishing emails made to look like Odido communications. 

Odido has about 7 million customers and has changed names several times over the last decade, including a recent run as T-Mobile Netherlands from 2021 to 2023. 

Cyberattacks on large national telecoms have roiled several countries in recent months. South Korea’s major mobile carrier, SK Telecom, told shareholders in November that recovery costs and other losses tied to a recent data breach led to a 90 percent drop in operating profit for the third quarter. The breach exposed the personal data of about 27 million customers. 

Last month, French regulators fined a French telecom giant Free SAS and sister company Free Mobile $42 million for an incident that exposed the personal data, including international bank account numbers, of 24 million subscribers.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support

Related Posts

SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers

Microsoft has revealed that it observed a multi‑stage intrusion that involved the threat actors exploiting internet‑exposed SolarWinds Web Help Desk (WHD) instances to obtain initial access and move laterally across the organization's network to other high-value assets. That said, the Microsoft Defender Security Research Team said it's not clear whether the activity weaponized recently
Read More

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691, carries a CVSS score of 10.0. It relates to a case of arbitrary file upload that could enable code execution without requiring any
Read More

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

Cybersecurity researchers have disclosed details of a new campaign that uses WhatsApp as a distribution vector for a Windows banking trojan called Astaroth in attacks targeting Brazil. The campaign has been codenamed Boto Cor-de-Rosa by Acronis Threat Research Unit. "The malware retrieves the victim's WhatsApp contact list and automatically sends malicious messages to each contact to further
Read More