Odido Suffers Cyberattack, Customer Data Compromised in Breach
Dutch telecommunications provider Odido disclosed a cyberattack on Thursday, confirming that customer data was compromised while maintaining that its services remained operational. The company, owned by private equity firms Apax Partners and Warburg Pincus, stated it swiftly contained the incident and reported the breach to the Authority for Personal Data.
Odido clarified that sensitive information such as passwords, call records, and invoice data was not accessed in the attack. However, due to the scale of the breach, the company plans to notify affected customers within 48 hours, though the exact number of impacted individuals was not specified.
The incident follows a separate cyberattack on the European Commission’s central mobile infrastructure reported on February 5, which potentially exposed staff names and mobile numbers. In response, the Commission emphasized its commitment to bolstering the EU’s cybersecurity resilience amid rising threats to critical services and institutions.
Odido TPRM report: https://www.rankiteo.com/company/odidonederland
European Commission TPRM report: https://www.rankiteo.com/company/european-union-agency-for-cybersecurity-enisa
"id": "eurodi1770907059",
"linkid": "european-union-agency-for-cybersecurity-enisa, odidonederland",
"type": "Breach",
"date": "2/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Telecommunications',
'location': 'Netherlands',
'name': 'Odido',
'type': 'Telecommunications Provider'}],
'customer_advisories': 'Plans to notify affected customers within 48 hours',
'data_breach': {'sensitivity_of_data': 'Non-sensitive (passwords, call '
'records, and invoice data were not '
'accessed)',
'type_of_data_compromised': 'Customer data'},
'description': 'Dutch telecommunications provider Odido disclosed a '
'cyberattack on Thursday, confirming that customer data was '
'compromised while maintaining that its services remained '
'operational. The company swiftly contained the incident and '
'reported the breach to the Authority for Personal Data. '
'Sensitive information such as passwords, call records, and '
'invoice data was not accessed in the attack. The company '
'plans to notify affected customers within 48 hours, though '
'the exact number of impacted individuals was not specified.',
'impact': {'data_compromised': 'Customer data',
'operational_impact': 'Services remained operational'},
'references': [{'source': 'Cyber Incident Description'}],
'regulatory_compliance': {'regulatory_notifications': 'Reported the breach to '
'the Authority for '
'Personal Data'},
'response': {'communication_strategy': 'Plans to notify affected customers '
'within 48 hours',
'containment_measures': 'Swiftly contained the incident',
'incident_response_plan_activated': 'Yes'},
'title': 'Odido Suffers Cyberattack, Customer Data Compromised in Breach',
'type': 'Data Breach'}