[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1lvkx730d57bw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":40,"seoTitle":41,"seoDescription":42,"logoUrl":43,"isVerified":4,"isSensitive":44,"isSpamList":44,"isMalware":44,"company":45},"6a452308a20f867c8ba8e743","odido","Odido Data Breach","odido.nl","2026-02-12T00:00:00.000Z","2026-02-26T23:25:29.000Z",null,"2026-07-03T09:35:48.387Z","2026-07-19T00:02:48.891Z","Third party breach","",[],6077025,"known","unknown","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"Critical",[29,30,31,32,33,34,35,36,37,38,39],"Bank account numbers","Customer service records","Dates of birth","Driver's licenses","Email addresses","Genders","Government issued IDs","Names","Passport numbers","Phone numbers","Physical addresses","\u003Cp>The Odido data breach was recorded as a large-scale incident in February 2026 affecting the customer records of the Netherlands-based telecom operator. The dataset, which contained approximately 6.08 million unique email addresses, was associated with customer data that emerged in four separate releases. Since the listed fields included bank account numbers, customer service records, dates of birth, driver's licenses, official identification information, passport numbers, phone numbers, and physical addresses, the incident carries critical privacy and identity fraud risks.\u003C\u002Fp> \u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2> \u003Cp>The types of data listed in this record are Bank account numbers, Customer service records, Dates of birth, Driver's licenses, Email addresses, Genders, Government issued IDs, Names, Passport numbers, Phone numbers, and Physical addresses. This combination brings together the identity, contact, address, bank, and support history context of a telecom customer in a single incident. The password field is not listed; however, the risk is very high due to identity and bank data.\u003C\u002Fp> \u003Ch2>Telecom Identity and Verification Risks\u003C\u002Fh2> \u003Cp>Telecom operators store information frequently used in customer authentication processes. When name, date of birth, address, phone number, passport or driver's license information, and customer service notes are present together, attackers can act like a real representative. Fake SIM changes, subscription renewals, bill corrections, authentication, device campaigns, or bank account verification messages are prominent risks in this context.\u003C\u002Fp> \u003Ch2>Bank and Identity Document Effect\u003C\u002Fh2> \u003Cp>The bank account numbers field is important in terms of payment and automatic collection fraud. A bank account number alone may not always be sufficient to withdraw money; however, when combined with the customer's name, address, phone number, and date of birth, it can be used in fake authorization or social engineering attempts. Affected customers should monitor their bank accounts for unusual instructions, automatic payment changes, or calls from fake customer representatives.\u003C\u002Fp> \u003Cp>Areas where passports, driver's licenses, and official IDs are obtained increase the risk of identity theft. These documents can be misused in processes such as new line applications, account recovery, credit applications, contract openings, or customer service verifications. Affected individuals should verify unexpected subscriptions, device installments, line transfers, SIM renewals, or ID requests through known official channels rather than through links in messages.\u003C\u002Fp> \u003Ch2>The Impact of Customer Service Records\u003C\u002Fh2> \u003Cp>The customer service records field can provide attackers with context about a user's previous issues and support history. For instance, past topics such as billing disputes, address changes, device problems, or subscription cancellations can be used in fake calls. If the user has actually received support before, a similar call may seem more convincing. Therefore, even calls that are aware of past support issues should not be automatically trusted.\u003C\u002Fp> \u003Cp>Phone number and physical address fields increase the risk of fraud through SMS, calls, and mail. Since telecom customers frequently receive campaign, billing, and technical support messages, fake messages can easily seem normal. Messages requesting verification codes, e-Government-like login, bank approval, SIM change, modem delivery, or device campaigns require special attention.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Customers affected by the Odido data breach should closely monitor their telecom account security settings, bank automatic payment instructions, and applications that can be made with identity documents. SIM changes or line transfer notifications should be kept active, bank transactions should be regularly checked, and no verification codes should be shared during unexpected calls. Even though this record does not contain a password, it is a critical data breach that requires long-term monitoring due to the scope of identity and banking information.\u003C\u002Fp> \u003Ch2>Long-Term Identity and Line Security\u003C\u002Fh2> \u003Cp>Long-term risk is particularly high in telecom breaches because phone numbers are used for two-factor authentication, account recovery, and bank communications in many services. Considering the phone, identity, and address fields together in the Odido record, attackers can make SIM swap or number porting attempts more convincing. Affected customers should assess these measures if additional security questions, line operation locks, or similar protections are offered on mobile operator accounts.\u003C\u002Fp> \u003Cp>Records containing identity documents and bank account numbers cannot be resolved with a one-time password change. Such data are fields that cannot be changed or are difficult to change and can be used in social engineering even years later. Therefore, Odido customers should carefully examine fake bank, telecom, cargo, official institution, or identity verification messages not only during the incident period but also in the following months. Suspicious application and subscription notifications should be reported to the relevant institution without delay.\u003C\u002Fp>","Odido Data Breach (6.1 Million Reported Records)","Odido Data Breach. 6.1 Million reported records are reported. Reported data: Bank account numbers, Customer service records, Dates of birth. Review the scope…","\u002Fuploads\u002Flogo\u002Fodido_nl.webp",false,{"name":46,"sector":47,"country":48,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"Odido","Telecommunications","Netherlands"]