---
title: "Odido and Ben customer-contact-system incident"
description: "Evidence-backed account of Odido and Ben customer-contact-system incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/odido-ben-customer-contact-system-incident-2026"
markdown_url: "https://www.ally.security/incidents/odido-ben-customer-contact-system-incident-2026.md"
stix_url: "https://www.ally.security/incidents/odido-ben-customer-contact-system-incident-2026/stix.json"
---

# Odido and Ben customer-contact-system incident

Two voice-phishing attacks against Odido customer service that led to unauthorized access and customer-data exfiltration affecting Odido and Ben customers. Exfiltrated customer-contact-system data with person-level impact reported by Odido and a separately measured verified HIBP corpus.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** A customer-contact-system field named password_c contained a challenge or code word for a limited group; Odido said it was not a login password, did not grant account access, and discontinued telephone verification based on it.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Two voice-phishing attacks against [Odido](https://www.odido.nl/) customer service that led to unauthorized access and customer-data exfiltration affecting Odido and Ben customers. [1](#source-1) [4](#source-4)

## Impact

Exfiltrated customer-contact-system data with person-level impact reported by Odido and a separately measured verified HIBP corpus. [4](#source-4)

Documented data types include:

- Demographic information — Nationality information, where present. [1](#source-1) [3](#source-3) [4](#source-4)
- Dates of birth — Dates of birth, where present. [1](#source-1) [3](#source-3) [4](#source-4)
- Driver's license numbers — Driver's-license identifiers listed in the verified HIBP corpus; Odido said scans of identity documents were not included. [1](#source-1) [3](#source-3) [4](#source-4)
- Passport numbers — Passport numbers listed in the verified HIBP corpus; Odido said scans of identity documents were not included. [1](#source-1) [3](#source-3) [4](#source-4)
- Gender information — Gender information, where present. [1](#source-1) [3](#source-3) [4](#source-4)
- Customer service records — Customer-service records and, in limited cases, additional information a person shared with customer service. [1](#source-1) [3](#source-3) [4](#source-4)
- Government-issued identifiers — Government-issued identification details; HIBP specifically listed European national ID numbers. [1](#source-1) [3](#source-3) [4](#source-4)
- Account credentials — A customer-contact-system field named password\_c contained a challenge or code word for a limited group; Odido said it was not a login password, did not grant account access, and discontinued telephone verification based on it. [1](#source-1) [3](#source-3) [4](#source-4)
- Financial account information — IBAN or bank-account numbers, where present; no assertion that banking login credentials were exposed. [1](#source-1) [3](#source-3) [4](#source-4)
- Usernames and account identifiers — Customer numbers used as account identifiers, where present. [1](#source-1) [3](#source-3) [4](#source-4)
- Names — Names, where present for an affected person. [1](#source-1) [3](#source-3) [4](#source-4)
- Contact information — Addresses, mobile numbers, and email addresses; the fields differed by person. [1](#source-1) [3](#source-3) [4](#source-4)

A cited record reports 6,390,000 individuals (Odido's approximate total of affected people, including active and inactive Odido and Ben customers; distinct from HIBP's unique-email count). [1](#source-1) [4](#source-4)

A cited record reports 6,077,025 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed count of people, customer accounts, files, or total rows; as of 2026-03-01). [1](#source-1) [3](#source-3)

HIBP reported that approximately 6 million unique email addresses were published across four data releases on consecutive days; Dutch police separately said data stolen from more than six million customers was later made public. [2](#source-2) [3](#source-3)

Odido said the affected data did not include Mijn Odido or other login passwords, call details, location data, billing data, invoice data, or scans of identity documents. [1](#source-1) [4](#source-4)

## Timeline

### February 5, 2026 — Documented event

Date of the first voice-phishing attack as stated by Odido; not asserted as a continuous intrusion start date. [1](#source-1)

### February 6, 2026 — Documented event

Date of the second voice-phishing attack as stated by Odido; not asserted as a continuous intrusion end date. [1](#source-1)

### February 12, 2026 — Public disclosure

Date of Odido's initial public newsroom notice. [4](#source-4)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Odido's operational services remained available and were not affected by the cyberattack. [4](#source-4)

Odido said Simpel customers were not impacted by the cyberattack. [1](#source-1) [4](#source-4)

### Actors

- ShinyHunters

### TTPs

- [T1566.004 — Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/) [1](#source-1)

## Response

Odido said its data analysis for the customer notifications had concluded. Dutch police reported strong indications that Dutch criminals were involved, including a Dutch-speaking caller who impersonated an Odido IT employee shortly before the hack. Dutch police said they took several servers used by the hacker group to distribute data offline during the early investigation. Odido said it immediately detected the unauthorized access in both attacks, investigated, revoked the threat actor's access, and worked with external cybersecurity experts. Odido said it contacted every customer it determined was affected by email or SMS, after initial and additional notifications. Odido did not pay the ransom, citing guidance from authorities and acknowledging that stolen data could consequently be published. Odido reported the incident to the Dutch Authority for Personal Data. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2) [4](#source-4)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/odido-ben-customer-contact-system-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Update about cyberattack

official · Odido

<https://www.odido.nl/veiligheid-eng>

<a id="source-2"></a>

### Onderzoek naar hack Odido wijst op mogelijke betrokkenheid Nederlanders

official · Politie Nederland · Jul 9, 2026

<https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html>

<a id="source-3"></a>

### Odido breach record

advisory · Have I Been Pwned · Feb 26, 2026

<https://haveibeenpwned.com/api/v3/breach/Odido>

<a id="source-4"></a>

### Odido informs customers of cyber attack

official · Odido · Feb 12, 2026

<https://newsroom.odido.nl/en-us/odido-informs-customers-of-cyber-attack/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Odido affected-customer and authority notifications: Odido said its data analysis for the customer notifications had concluded.
2. **Resulted In · 85% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Dutch police reported strong indications that Dutch criminals were involved, including a Dutch-speaking caller who impersonated an Odido IT employee shortly before the hack.
3. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Demographic information
4. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido's operational services remained available and were not affected by the cyberattack.
5. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido said Simpel customers were not impacted by the cyberattack.
6. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Dutch police said they took several servers used by the hacker group to distribute data offline during the early investigation.
7. **Resulted In · 95% confidence · current**  
   Odido and Ben customer-contact-system data exposure: HIBP reported that approximately 6 million unique email addresses were published across four data releases on consecutive days; Dutch police separately said data stolen from more than six million customers was later made public.
8. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido affected-customer and authority notifications
9. **Used Attack Technique · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: https://attack.mitre.org/techniques/T1566/004/
10. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Dates of birth
11. **Affected Individual Count · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: 6,390,000 individual
12. **Exposed Data Category · 95% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Driver's license numbers
13. **Affected Organization · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Ben
14. **Exposed Data Category · 95% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Passport numbers
15. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido said it immediately detected the unauthorized access in both attacks, investigated, revoked the threat actor's access, and worked with external cybersecurity experts.
16. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Gender information
17. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Customer service records
18. **Exposed Data Category · 95% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Government-issued identifiers
19. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Account credentials
20. **Resulted In · 100% confidence · current**  
   Odido affected-customer and authority notifications: Odido said it contacted every customer it determined was affected by email or SMS, after initial and additional notifications.
21. **Resulted In · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Odido said the affected data did not include Mijn Odido or other login passwords, call details, location data, billing data, invoice data, or scans of identity documents.
22. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Financial account information
23. **Occurred At · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: 2026-02-05
24. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Usernames and account identifiers
25. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Names
26. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido did not pay the ransom, citing guidance from authorities and acknowledging that stolen data could consequently be published.
27. **Exposed Record Count · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: 6,077,025 record
28. **Exposed Data Category · 100% confidence · current**  
   Odido and Ben customer-contact-system data exposure: Contact information
29. **Disclosed At · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: 2026-02-12
30. **Occurred At · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: 2026-02-06
31. **Attributed To · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: ShinyHunters
32. **Resulted In · 100% confidence · current**  
   Odido affected-customer and authority notifications: Odido reported the incident to the Dutch Authority for Personal Data.
33. **Resulted In · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido and Ben customer-contact-system data exposure
34. **Affected Organization · 100% confidence · current**  
   February 2026 Odido customer-contact-system cyberattack: Odido

</details>
