logo

Odido Breach: How a Single CRM System Handed 6.2 Million Identity Theft Starter Kits to Unknown Attackers

ID: cd3d72f1-ca22-5a0b-9c5c-f6bdb1c4bdb6

STIX ID: report--cd3d72f1-ca22-5a0b-9c5c-f6bdb1c4bdb6

Feed Name: NoHackie

Threat Score
88/100

Date Published: 2026-02-15

Date Updated: 2026-04-19

...
...

On the weekend of 7–8 February 2026 Odido, the Netherlands' largest mobile carrier, detected unauthorized access to a customer contact (CRM) system and later disclosed a breach affecting about 6.2 million customer accounts. Exfiltrated fields reportedly include full names, addresses, phone numbers, email addresses, account numbers, dates of birth, IBANs, and passport/driver's license numbers; attackers directly contacted Odido suggesting an extortion motive. The report highlights CRM systems as high-value targets, a failure of detection (the attacker, not internal systems, first alerted the company), substantial fraud and identity-theft risks (precision phishing, SIM-swap, synthetic identities), and significant regulatory exposure under GDPR and NIS2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.