Background and Timeline: On February 13, 2026, Odido, the largest mobile provider in the Netherlands, confirmed a massive data breach. The incident was detected over the weekend of February 7-8 when attackers successfully infiltrated a customer contact system. Odido was reportedly alerted to the breach by the attackers themselves, who claimed to have stolen millions of records.
Modus Operandi: Hackers compromised a Customer Relationship Management (CRM) system and downloaded a vast trove of sensitive information. The company stated that while core systems were secure, the customer contact platform served as a repository for identification and contact details. The attackers likely exploited an unaddressed weakness in the system’s access controls to exfiltrate the data without triggering internal alarms.
Victims and Financial Impact: The breach affects 6.2 million customers, exposing full names, addresses, mobile numbers, dates of birth, and bank account numbers (IBAN). In some cases, identification data such as passport and driver’s license numbers were also exfiltrated. The exposure creates an immediate and severe risk of identity theft and sophisticated financial fraud for a significant portion of the Dutch population.
Investigation and Agencies Involved: Odido has engaged external cybersecurity experts to conduct a forensic probe and has reported the breach to the Dutch Data Protection Authority. The company has strengthened its security controls and set up a dedicated support page for affected users. The fact that attackers alerted the company highlights a potential gap in detection capabilities that Odido is currently reviewing.
Arrests and Suspects: No specific group has publicly claimed responsibility yet, though the scale points to a professional cyber-extortion syndicate. Investigators are analyzing whether the breach is linked to “World Leaks,” a data extortion group that has recently targeted other global companies. The compromised data has not yet appeared on dark web leak sites, suggesting that negotiations may be ongoing.
Broader Implications and Trends: This incident underscores the systemic risk facing critical telecommunications infrastructure worldwide. It serves as a reminder of the “cascading consequences” of a single system compromise, particularly within CRM systems that store highly sensitive identifiers. The breach reinforces the necessity for robust, multi-layered security and continuous monitoring of third-party operational tools.