Summary
- Environment: A customer-contact-system field named password_c contained a challenge or code word for a limited group; Odido said it was not a login password, did not grant account access, and discontinued telephone verification based on it.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Exfiltrated customer-contact-system data with person-level impact reported by Odido and a separately measured verified HIBP corpus. [4]
Documented data types include:
- Demographic information — Nationality information, where present. [1][3][4]
- Dates of birth — Dates of birth, where present. [1][3][4]
- Driver’s license numbers — Driver’s-license identifiers listed in the verified HIBP corpus; Odido said scans of identity documents were not included. [1][3][4]
- Passport numbers — Passport numbers listed in the verified HIBP corpus; Odido said scans of identity documents were not included. [1][3][4]
- Gender information — Gender information, where present. [1][3][4]
- Customer service records — Customer-service records and, in limited cases, additional information a person shared with customer service. [1][3][4]
- Government-issued identifiers — Government-issued identification details; HIBP specifically listed European national ID numbers. [1][3][4]
- Account credentials — A customer-contact-system field named password_c contained a challenge or code word for a limited group; Odido said it was not a login password, did not grant account access, and discontinued telephone verification based on it. [1][3][4]
- Financial account information — IBAN or bank-account numbers, where present; no assertion that banking login credentials were exposed. [1][3][4]
- Usernames and account identifiers — Customer numbers used as account identifiers, where present. [1][3][4]
- Names — Names, where present for an affected person. [1][3][4]
- Contact information — Addresses, mobile numbers, and email addresses; the fields differed by person. [1][3][4]
A cited record reports 6,390,000 individuals (Odido’s approximate total of affected people, including active and inactive Odido and Ben customers; distinct from HIBP’s unique-email count). [1][4]
A cited record reports 6,077,025 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed count of people, customer accounts, files, or total rows; as of 2026-03-01). [1][3]
HIBP reported that approximately 6 million unique email addresses were published across four data releases on consecutive days; Dutch police separately said data stolen from more than six million customers was later made public. [2][3]
Odido said the affected data did not include Mijn Odido or other login passwords, call details, location data, billing data, invoice data, or scans of identity documents. [1][4]
Timeline
Documented event
Date of the first voice-phishing attack as stated by Odido; not asserted as a continuous intrusion start date.
[1]Documented event
Date of the second voice-phishing attack as stated by Odido; not asserted as a continuous intrusion end date.
[1]Public disclosure
Date of Odido’s initial public newsroom notice.
[4]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Response
Odido said its data analysis for the customer notifications had concluded. Dutch police reported strong indications that Dutch criminals were involved, including a Dutch-speaking caller who impersonated an Odido IT employee shortly before the hack. Dutch police said they took several servers used by the hacker group to distribute data offline during the early investigation. Odido said it immediately detected the unauthorized access in both attacks, investigated, revoked the threat actor’s access, and worked with external cybersecurity experts. Odido said it contacted every customer it determined was affected by email or SMS, after initial and additional notifications. Odido did not pay the ransom, citing guidance from authorities and acknowledging that stolen data could consequently be published. Odido reported the incident to the Dutch Authority for Personal Data. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2][4]
