{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"},"incident":{"slug":"2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli","title":"Odido staff phished then called by fake IT department, exposing 6.2 million Dutch customers","date":"2026-02","date_precision":"month","year":2026,"victim_org":"Odido (and subsidiary Ben)","sector":"Telecom","country":"Netherlands","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Spear Phishing (Email)","MFA Fatigue / Push Bombing"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":6200000,"threat_actor":null,"summary":"Dutch mobile operator Odido detected a cyberattack on its customer contact system over the weekend of 7 February 2026 and disclosed it on 13 February. Dutch public broadcaster NOS reported that attackers first harvested customer service employees' passwords with phishing emails, then telephoned those employees while posing as Odido's own ICT department to get them to approve the fraudulent login attempts and bypass two-factor authentication. The system reached was Odido's Salesforce environment, from which customer data was scraped in bulk. About 6.2 million current and former Odido and Ben customers were notified, and the breach was reported to the Dutch Data Protection Authority.","how_it_worked":"Stage one was a phishing email to customer service staff that captured their Odido passwords. Stage two closed the gap left by two-factor authentication: the attackers telephoned the same employees, introduced themselves as Odido's internal ICT department, and framed the login prompt appearing on the employee's device as routine IT maintenance or a system check the employee needed to approve. Because the caller already knew the employee's username and password and could describe the prompt they were about to see, the call carried strong insider credibility. Once approved, the attackers held a valid Salesforce session and used automated page scraping to pull customer records at scale.","lessons":"Number matching or phishing-resistant MFA instead of simple approve prompts, combined with rate limiting and anomaly alerting on bulk record reads in Salesforce, would have stopped both the approval trick and the mass scraping that followed.","confidence":"Reported","sources":[{"title":"Odido-hackers kwamen binnen via phishing, deden zich voor als ICT-afdeling","url":"https://nos.nl/artikel/2602283-odido-hackers-kwamen-binnen-via-phishing-deden-zich-voor-als-ict-afdeling","publisher":"NOS"},{"title":"Major hack of Dutch telco Odido was a classic case of social engineering","url":"https://www.techzine.eu/news/security/138787/major-hack-of-dutch-telco-odido-was-a-classic-case-of-social-engineering/","publisher":"Techzine"},{"title":"Odido data breach exposes personal info of 6.2 million customers","url":"https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-odido-staff-phished-then-called-by-fake-it-department-exposing-6-2-milli"}}