Data breach
Odido
- Records
- 6,598,287
- Breach date
- 4 March 2026Estimated
- Added
- 9 March 2026
What was exposed
4 types of data · 3 more reported
- Dates of birth6,598,287
- Email addresses5,873,551
- Phone numbers5,048,030
- Names4,941,694
- Bank account numbersReported, not counted
- Home addressesReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Dutch telecom provider Odido, formerly T-Mobile Netherlands, suffered one of the largest data breaches in the country's history after a criminal group known as ShinyHunters accessed its customer systems. According to our investigation team, the indexed dataset contains 6,598,287 records, with dates of birth present for all of them, email addresses for 5,873,551, phone numbers for 5,048,030, and names for 4,941,694. Odido itself estimates that roughly 6.39 million people, including customers of its Ben brand, were affected. The hackers demanded a ransom, Odido refused to pay, and the group began publishing the stolen data on the dark web.
Breach Timeline
February 5 and 6, 2026: Attackers posing as Odido IT staff carried out voice phishing calls against customer service employees, gaining access to the customer system, according to Odido's notice.
February 12, 2026: Odido confirmed the cyberattack and said personal data of millions of current and former customers was exposed.
February 26, 2026: ShinyHunters began leaking customer records on the dark web after Odido declined to pay, as reported by Reuters.
April 20, 2026: The privacy foundation Consumers United started a collective court action against Odido, according to TPO.
What Information Was Compromised?
Our analysis found the following data types in this breach: dates of birth, email addresses, phone numbers, and names.
Odido's own notice lists further fields that differ per person: names, addresses, mobile numbers, customer numbers, email addresses, IBAN bank account numbers, dates of birth, identification details, nationality, and gender. The notice also states that a field called "password_c" leaked. Despite the name, Odido says this is a telephone verification code word, not an account password, and no login passwords, call details, location data, billing data, or scans of identity documents were taken. Dutch media, including NOS and RTL, reported that the published files also contained internal customer service notes about people with payment problems.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
With names, addresses, birth dates, phone numbers, and in some cases bank account numbers, criminals can craft highly convincing phishing messages pretending to be Odido, a bank, or a government agency. IBAN numbers alone do not grant access to bank accounts, but they are valuable for fake invoices and payment fraud. Identification details raise the risk of identity fraud, and the National Identity Fraud Reporting Office registered a sharp increase in confirmed fraud reports in the week after the leak, mainly phone number takeovers, fake invoices, and WhatsApp fraud. Because the data is circulating openly on the internet, misuse may surface long after the initial news coverage fades.
What Is Odido Doing in Response?
Odido refused to pay the ransom, citing advice from police and cybersecurity firms. The company notified affected customers by email or SMS, discontinued the code word verification method, and is reviewing its data retention practices. The Dutch Public Prosecution Service has opened a criminal investigation, and the Dutch Data Protection Authority is examining whether Odido's security measures were adequate. The collective compensation claim filed in April is ongoing, and investigations remain active as of April 20, 2026.
What Should You Do If You Were Affected?
Check whether you received a notification from Odido, and verify whether your data appears in the leak through the Dutch police's "Check je hack" website. Be skeptical of unexpected calls, texts, or emails, even if they mention your name or account details, and contact companies directly through official channels. Monitor your bank transactions and enable notifications with your bank. Register with the Central Identity Fraud Reporting Office if you suspect misuse, and consider a fraud alert with a credit reporting agency. Report any fraud to your bank and the police, and keep any documents Odido sent you about the breach.
In the news
- Odido update about the cyberattackodido.nl (opens in a new tab)
- Reuters: Hacking group begins leaking customer data in Dutch telecom Odido hackreuters.com (opens in a new tab)
- NL Times: Hackers publish 680,000 Odido customer records, demand ransomnltimes.nl (opens in a new tab)
- NL Times: Data of ministers, protected individuals found in massive Odido hacknltimes.nl (opens in a new tab)
- TPO: Massaclaim tegen Odido na datalek miljoenen klanten
