Odido Data Breach Exposes Personal Information of 6.2 Million Customers

Related

Multiple US Healthcare Data Breaches Expose Millions of Patient Records

What happened Several major healthcare data breaches have been added...

Grafana Labs Refuses to Pay Ransom After Codebase Theft

What happened Grafana Labs confirmed over the weekend that an...

UK Water Company Fined After Hackers Lurked Undetected for Nearly Two Years

What happened The UK's Information Commissioner's Office fined South Staffordshire...

Å koda Online Shop Security Incident Exposes Customer Data

What happened Å koda Auto has disclosed a security incident affecting...

Share

What happened

Dutch telecommunications provider Odido disclosed that a cyberattack exposed personal data belonging to approximately 6.2 million customers after attackers breached its customer contact system. The company detected the incident on February 7 and launched an investigation with internal and external cybersecurity experts. According to Odido, threat actors gained unauthorized access to a customer contact system and downloaded personal information stored in that environment. Exposed data may include full names, addresses, mobile numbers, email addresses, customer numbers, IBAN account numbers, dates of birth, and identification data such as passport or driver’s license details. Odido stated that passwords, call logs, billing information, and identification document scans were not affected. The company blocked unauthorized access, reported the breach to the Dutch Data Protection Authority, and began notifying impacted customers while strengthening monitoring and security controls. 

Who is affected

Approximately 6.2 million customers of Odido are affected, as attackers accessed personal information stored in the company’s customer contact system, including identifying and contact details associated with telecommunications accounts. 

Why CISOs should care

The compromise of a telecommunications provider’s customer contact system highlights how centralized customer data repositories can become high-value targets for attackers seeking large volumes of personal and financial information. 

3 practical actions

  • Secure customer contact systems. Ensure access controls and monitoring protect centralized repositories containing customer information.
  • Notify affected individuals. Inform impacted customers promptly and provide guidance on protecting their personal data.
  • Strengthen security monitoring. Increase detection and response capabilities to identify unauthorized access and prevent further compromise.
IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.