Odido Breach Victims Are Still Getting Phishing Emails, Five Months Later, and It Could Get Worse

Home Opinion CISO Perspective Odido Breach Victims Are Still Getting Phishing Emails, Five Months Later, and It Could Get Worse
Odido Breach Victims Are Still Getting Phishing Emails, Five Months Later, and It Could Get Worse, Infosec Federation

Five months after Dutch telecom provider Odido confirmed one of the largest data breaches in Dutch history, its customers are still opening phishing emails built from the stolen records, according to research from Dutch cybersecurity firm Hackify, reported by Dutch IT Leaders and ICT Magazine. Hackify tracked two dedicated inboxes tied only to Odido and its Tele2 brand and logged 61 phishing messages over 150 days, the first arriving just eleven days after the leaked dataset went up for sale on the dark web. For security leaders, the finding is a reminder that a breach’s fallout does not end with the notification email. It can run for months, and researchers warn the worst abuse may still be ahead.

What did the Hackify research actually find?

Hackify researcher Rick Verdoes and a colleague set up two catch-all email addresses used nowhere else except in their own Odido and Tele2 accounts, according to Dutch IT Leaders. Because the addresses had no other public footprint, any phishing that reached them could only have originated from the leaked Odido dataset. Over the 150-day study period the two inboxes collected 61 phishing emails between them: 32 landed on the Odido-linked address, 29 on the Tele2-linked address, and 28 reached both, ICT Magazine reported. The messages impersonated the Dutch Chamber of Commerce, banks, prize draws, parcel couriers and government agencies, according to Bright.nl’s account of the same study. Only one of the 61 messages addressed the recipient by name, despite the underlying dataset containing full names, home addresses and bank details, the outlets reported, suggesting criminals have so far weaponized mostly the email addresses themselves rather than the richer identity data sitting alongside them in the leak.

What happenedPhishing emails built from Odido’s leaked customer data are still arriving five months after the breach, according to research from Dutch cybersecurity firm Hackify.
WhenBreach: February 2026. Dataset published on the dark web: March 1, 2026. Hackify tracked phishing for 150 days after that, into early July 2026.
Who is affectedMore than 6.2 million current and former Odido and Tele2 customers whose names, addresses, phone numbers and bank details were exposed.
Scale61 phishing emails logged by two dedicated research inboxes; roughly 275,000 IBANs from the breach remain unaccounted for.
Fix or deadlineNo fix restores the leaked data. A class action seeking $540 (500 euros) per victim is open to Odido, Ben, T-Mobile and Tele2 customers; Dutch police are still hunting the hackers.
Where the 61 phishing emails landed
Odido-linked address
32
Tele2-linked address
29
Reached both addresses
28

Why are victims still being targeted five months later?

The timeline traces back to how the breach unfolded. Odido confirmed in February that attackers linked to the ShinyHunters group, the same crew whose data-theft campaign against Salesforce customers also hit Canva and Instructure, had broken into a Salesforce-hosted customer contact system by phishing staff and impersonating the company’s own IT department to bypass multi-factor authentication, according to DutchReview. When Odido did not meet the group’s demands, ShinyHunters published the full dataset, covering names, addresses, phone numbers, bank account numbers and identity document details for more than 6.2 million current and former customers, to the dark web on March 1, DutchReview reported. Hackify’s monitoring shows the resulting phishing did not arrive in one wave. The first message landed on March 12, volume built over the following months, and then activity stopped abruptly after July 3 with no clear explanation, according to Dutch IT Leaders, with Bright.nl noting dryly that the criminals might simply be on vacation. Separately, thousands of Dutch residents have reported fake traffic-fine emails impersonating CJIB, the government’s central fines agency, demanding $162 to $734 (150 to 680 euros) and linking to counterfeit payment pages, according to NL Times. NL Times reported the campaign’s timing and its narrow targeting of former Odido subscribers pointed to the stolen data being cross-referenced for fraud; CJIB has said it never contacts people about fines by email.

How much worse could this get?

The unsettling part of Hackify’s findings is what criminals have not yet done with the data. Roughly 275,000 IBANs from the breach remain unaccounted for, and researchers warned that once attackers start combining a victim’s name, address and bank details in a single message, the result becomes far harder to distinguish from a legitimate one, the kind of tailored approach known as spear phishing. Some Odido customers have separately reported phone calls from scammers using AI-generated voices, posing as compensation-claim handlers before asking for bank details, a tactic that mirrors the AI-driven impersonation fraud tracked in our coverage of voice cloning and deepfake scams targeting consumers. Given how long stolen personal records stay tradeable on dark web markets, Odido’s millions of affected customers should plan for exposure that lasts years, not months.

What is the broader fallout for Odido?

Dutch police are still pursuing the people behind the intrusion. Investigators have named a suspect and released a recording of a voice believed to belong to the caller who posed as Odido IT staff, hoping the public can help identify him, according to NL Times. Separately, the privacy foundation Consumers United in Court has opened a class action seeking $540 (500 euros) per victim, open to any current or former customer of Odido, Ben, T-Mobile or Tele2, though DutchReview reports the case could take up to two years to resolve.

What should security leaders do about it?

Odido’s slow-burn phishing problem is a case study in how a single social-engineering call to a support desk can generate liability long after the breach notification goes out, a pattern our coverage of Adobe’s BPO breach also traced back to one phished support agent. Two lessons apply broadly. First, support staff and CRM users who can view or reset customer records need phishing-resistant authentication, not just MFA that a convincing phone call can talk someone into approving. Second, customer-facing breach communications cannot be a single notification. Hackify’s data shows phishing attempts were still arriving five months on, so awareness messaging and monitoring for brand impersonation need the same long tail, a point our comparison of security awareness training and human risk management makes for exactly this kind of scenario. Breaches involving financial identifiers, as seen in comparable incidents like the Bank of Baroda data leak, tend to keep generating fraud reports well past the initial news cycle, and boards should budget monitoring and customer support accordingly rather than treating breach response as a one-time cost.

Frequently asked questions

What did Hackify’s research find about phishing after the Odido breach?

Dutch cybersecurity firm Hackify tracked two email addresses used only for its own Odido and Tele2 accounts and logged 61 phishing emails over 150 days, according to Dutch IT Leaders. The first arrived 11 days after the stolen dataset was published, and most messages impersonated banks, government agencies and delivery services rather than using victims real names.

Why are Odido customers still receiving phishing emails months after the breach?

The Odido dataset, including names, addresses and bank details for more than 6.2 million customers, was published on the dark web on March 1, 2026 after the ShinyHunters group’s demands reportedly went unmet, according to DutchReview. Researchers found the resulting phishing arrived in waves rather than all at once, with activity continuing into July.

What should people affected by the Odido breach do now?

Affected customers should treat unexpected emails or calls referencing fines, refunds or account issues as suspicious, verify requests independently through official websites, and avoid clicking embedded links, researchers advised. Roughly 275,000 IBANs from the leak remain unaccounted for, so unsolicited requests for bank details deserve particular caution.

Leave a Reply

Your email address will not be published.