On 12 February 2026, Odido—the Netherlands' largest telecommunications provider (formerly T-Mobile Nederland)—confirmed that hackers had gained unauthorized access to its systems and exfiltrated a file containing personal data for potentially 6.2 million people. The breach represents one of the largest telecom data exposures in Dutch history and underscores the risks of consolidation in critical infrastructure.
What happened
Odido's spokesperson confirmed to Dutch broadcaster NOS that attackers had broken into the company's systems and accessed a file from a customer contact system used by the telecom provider. The breach did not affect core telecom services—customers could continue making calls, using the internet, and watching television as usual. However, the exfiltrated data contained highly sensitive personally identifiable information (PII) that could enable identity theft, fraud, and targeted phishing.
Data compromised
According to Odido's disclosure, the accessed file included:
- Full names
- Physical addresses
- Phone numbers
- Customer numbers
- Email addresses
- Account numbers (potentially including IBANs for direct debit)
- Date of birth
- Passport and driver's license information
Odido stated that passwords, call logs, and billing information were not involved in the breach—a small consolation given the severity of the identity document exposure.
Technical context
Customer contact systems (CCS) and customer relationship management (CRM) platforms are common targets for threat actors because they aggregate PII across the customer lifecycle. Access to such systems often stems from:
- Compromised employee or service accounts
- Vulnerabilities in third-party integrations
- Phishing or credential theft
- Insufficient access controls or segmentation
Odido has not disclosed the specific attack vector or whether the threat actor has been identified. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has been notified, and Odido pledged to email all affected customers as soon as possible.
Regulatory and historical context
Odido (formerly T-Mobile Nederland until its 2023 rebrand) has a history of regulatory scrutiny. In March 2024, the Dutch digital infrastructure inspectorate (RDI) fined the company €175,000 for improperly processing traffic and location data from 2.5–4.5 million subscribers between 2018 and 2019. In a separate case, RDI imposed a €1.52 million fine for wiretapping system security failures. The February 2026 breach adds a significant incident to the company's security record.
Recommendations for affected users
- Monitor for phishing — Attackers may use your name, address, and identity details to craft convincing scams.
- Enable account alerts — Set up notifications for banking and financial account activity.
- Consider a credit freeze — If identity documents were exposed, consider restricting access to your credit file.
- Change passwords — Although Odido says passwords were not involved, update credentials on any accounts that may have been reused.
- Expect official communication — Odido will email affected customers; be cautious of phishing attempts claiming to be from Odido.
Bottom line
The Odido breach exposes nearly half of the Dutch population's personal data to unknown threat actors. The combination of identity documents, account numbers, and contact details creates a high risk of identity fraud and targeted attacks. For the latest breach timeline and technical details, see Odido 2026 breach on BreachHistory.
Source: NL Times