Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedConfirmed

Odido: IT impersonation calls and MFA approval requests expose 6.2M customers

Odido · Telecom · Netherlands · February 2026

People or records affected
6,200,000
6.2M as reported

What happened

Dutch mobile operator Odido, formerly T-Mobile Netherlands, disclosed in February 2026 that attackers reached its Salesforce CRM and scraped data on 6.2 million customers. Exposed fields included names, addresses, phone numbers, customer IDs, bank account numbers, dates of birth and government identification numbers such as passport and driving licence details. Network services were unaffected and no group claimed the breach.

How the deception worked

The intrusion combined two human steps. Phishing emails went to customer service staff asking for login credentials, and separately attackers telephoned other employees while posing as Odido's own IT department, asking them to approve login attempts that were in fact the attackers' sessions. Approving that push satisfied multi-factor authentication and handed over an authenticated Salesforce session. Once inside the CRM the attackers ran scraping software to extract customer records at scale rather than querying record by record.

The control that would have caught it· our reading, not a claim from the sources

Number-matched or phishing-resistant MFA removes the blind approval, and rate limiting plus anomaly alerting on CRM record retrieval catches the scraping stage before millions of rows leave.

Sources (2)

  1. Odido hackers pretended to be an IT employee to breach corporate system
    Cybernews·cybernews.comOpen ↗
  2. Odido Salesforce Hack: Up to 6M Customers' Data at Risk
    Salesforce Ben·salesforceben.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.