Odido, the largest mobile telecommunications provider in the Netherlands, has confirmed a significant data breach affecting approximately 6.2 million individuals. While the company's core operational networks remain secure, the attackers successfully exfiltrated a large volume of sensitive personal information.Â
The company revealed that cybercriminals gained unauthorized access to a customer contact system on February 7.
According to Odido CEO Søren Abildgaard, investigators traced the intrusion to a specific support system used for customer contact. The attackers exploited this entry point to exfiltrate data before security teams detected the anomaly and severed the connection. Stolen data includes:
The company has stated that current services remain unaffected, and no specific cybercriminal group has yet claimed responsibility for the attack. Odido will notify impacted customers directly.
Odido has warned customers in its release that criminals may attempt to impersonate company officials using these stolen verification details to gain further access to personal accounts or finances.
This incident highlights the growing risk of supply chain vulnerabilities in telecom cybersecurity. This month, the UNC3886 Cyberespionage group was linked to cyberattacks on Singapore telecom companies Singtel, StarHub, M1, and Simba Telecom, and China-nexus espionage APT UAT-7290 targeted telecom infrastructure in South Asia.