Dutch police link local hackers to Odido telecom breach: What Was Exposed & What To Do
Dutch police have linked local hackers to a breach at Odido telecom that exposed the names, addresses, phone numbers, email addresses, and IBAN details of 6.2 million customers on July 10, 2026. Check if your data was involved and take steps to protect your accounts.
Inside the incident
The Dutch National Police reported that attackers used vishing and phishing techniques to gain access to Odido’s customer contact system in February 2026. The breach resulted in the theft of records belonging to 6.2 million customers. The police announcement on July 10, 2026, indicated that Dutch hackers were involved, based on their investigation. A group known as ShinyHunters had previously claimed responsibility and published a large archive of records online.
Exact details on how long the access persisted, the precise entry point within the contact system, or the full volume of data taken have not been disclosed by Odido or the police.
How a breach like this happens
Incidents involving customer contact systems often begin with social-engineering methods such as vishing or phishing. Attackers impersonate trusted parties to obtain credentials or persuade staff to grant remote access. Once inside, they can query or export customer records stored in those platforms. Such systems frequently hold aggregated personal and account information because they are designed to support rapid customer service interactions.
Public reporting on this case has not attributed a specific technical vulnerability or confirmed whether additional controls were bypassed after initial access.
About Odido
Odido operates as a telecommunications provider in the Netherlands, serving residential and business customers with mobile, fixed-line, and internet services. Like other firms in this sector, it maintains large databases of subscriber information to manage accounts, billing, and service delivery. A breach at this scale affects a substantial portion of the national population and involves data routinely used for identity verification and financial transactions.
The information in question
The police statement and associated reporting identify the exposed data as names, addresses, phone numbers, email addresses, IBAN bank account numbers, dates of birth, and ID details. These categories align with the information typically stored in a telecom customer contact system. No further breakdown of file counts, additional data fields, or confirmation of encryption status has been released publicly.
The real-world impact
Exposure of names, addresses, dates of birth, and ID details can facilitate identity-verification fraud or targeted phishing. Inclusion of IBAN numbers raises the possibility of attempted unauthorized transactions or account takeover attempts if combined with other details. For the organisation, the incident triggers regulatory scrutiny under Dutch and EU data-protection rules and may require notification to affected customers and supervisory authorities.
Longer-term consequences for individuals depend on whether the data is used in further criminal activity, which remains outside the scope of currently What's Publicly Reported.
Were you affected?
Odido has not published a public lookup tool for affected customers. Individuals can contact the company directly using official channels listed on its website to inquire about their account status. Running a free exposure scan of an email address against known breach datasets can indicate whether the address appears in publicly discussed leaks, though such scans do not confirm inclusion in this specific incident. Monitoring bank statements and official communications for unusual activity remains a standard precaution when personal and financial identifiers have been exposed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Charter Communications Confirms Breach After ShinyHunters ExtortionAccenture confirms breach after 35GB source code offered for saleUnsafe ransomware group claims Deutsche Bank data breachArmored Likho Deploys BusySnake Stealer Against Critical InfrastructureLatest breaches
Read GalaxyWarden’s full analysis of the Dutch police link local hackers to Odido telecom breach →
Publicly posted — pending verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.