Fake IT Caller Tied to Odido Phishing Breach

Security Affairs · Medium sophistication
Last updated July 30, 2026

Dutch police say the February 2026 breach at Dutch telecom Odido, where data on more than six million customers was stolen, was enabled by social engineering and phishing. Investigators cite a Dutch-speaking caller who allegedly posed as an Odido IT employee shortly before the intrusion, after which phishing led to the compromise and data theft.

How the Attack Unfolded

According to Dutch police, the breach at telecom provider Odido began with a phone call to customer service shortly before the intrusion. During that call, a Dutch-speaking man posed as an internal IT employee. Odido has stated that the company was then compromised through phishing, after which attackers accessed a customer contact system and stole data belonging to more than six million customers. The cybercrime group ShinyHunters is described as having broken into Odido and accessed data from 6.2 million accounts.

Why This Pretext Worked

Impersonating internal IT is effective because customer service and call center staff are trained to be helpful and responsive, especially when a request appears to come from within the organization. A caller claiming to have a vague 'system issue' can create just enough urgency to bypass normal skepticism, particularly if the request seems routine, such as looking up account details or adjusting settings. Once that initial vishing contact softened the target, a follow-up phishing message reportedly completed the compromise, showing how voice and email channels can be chained together in a single campaign.

What Was Exposed

The stolen data included names, addresses, phone numbers, email addresses, bank account details, dates of birth, and passport or ID numbers. Odido said passwords, call logs, and billing information were not affected. Even without credential exposure, this volume of personal data creates real risk for follow-on scams targeting affected customers.

Red Flags to Watch For

  • An unverified caller claiming to be internal IT and referencing a vague technical problem
  • Pressure or urgency tied to resolving that

Key findings

  • Police found indications of Dutch nationals’ involvement, including a phone call to customer service shortly before the hack.
  • A Dutch-speaking man allegedly impersonated an Odido IT employee during that call.
  • Odido stated the company was 'compromised through phishing' and that attackers accessed a customer contact system.
  • Stolen data included names, addresses, phone numbers, email addresses, bank account details, dates of birth, and passport/ID numbers; Odido says passwords were not affected.
  • The cybercrime group ShinyHunters is described as having broken into Odido and accessed data from 6.2 million accounts.
  • Police took offline servers used to distribute the stolen data.

Who’s being targeted

  • Commonly targeted roles: Customer Service, Call Center, IT Helpdesk, Employees with access to customer contact/CRM systems, Security Awareness Program Stakeholders.
  • Affected industries: Telecommunications.
  • Attack channels: vishing, email.
  • Impersonated: Odido IT employee, Internal IT / corporate system notification (not further specified).

Red flags to watch for

  • Unverified caller claiming to be internal IT
  • Urgency or pressure tied to a vague 'system issue'
  • Request to perform access-related actions without standard verification
  • Unexpected 'IT' message prompting immediate action
  • Link requesting login details
  • Message context not aligned with normal IT communications
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Odido breach start?

Dutch police found a Dutch-speaking man called Odido customer service shortly before the hack and posed as an internal IT employee, and the company was then compromised through phishing.

What data was exposed in the Odido breach?

Stolen data included names, addresses, phone numbers, email addresses, bank account details, dates of birth, and passport or ID numbers, though Odido said passwords were not affected.

Who is linked to the Odido attack?

The cybercrime group ShinyHunters is described as having broken into Odido and accessed data from 6.2 million accounts.

How can companies defend against this type of attack?

Train customer-service staff to treat internal-IT phone requests as high-risk, require call-back verification before any access-related action, and reinforce phishing defenses for staff with access to customer contact systems.

Read the video transcript

“Hi, this is IT from Odido…”, one phone call like that helped expose data from 6.2 million customer accounts. Dutch police say a Dutch-speaking man posed as an Odido IT employee, called customer service, then a phishing email did the rest, giving access to a customer contact system and all that personal data. Here’s the pattern: unverified ‘internal IT’ caller, vague urgent “system issue,” then an email pushing you to click a link and log in. That combo is exactly how Odido was compromised through phishing. If someone calls saying, “This is IT,” and wants access or changes, end the call and ring them back on an official number you look up yourself, no exceptions.

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026