← Terug naar inzichten Datalekken & social engineering

The Aftermath of the Odido Hack

Smartphone met het Odido-logo op een toetsenbord, met tekst van hackersgroep ShinyHunters op de achtergrond

English below

Eén telefoontje naar en helpdesk-medewerker die zijn werk deed. En vervolgens lagen de gegevens van miljoenen Nederlanders op straat. Dit is hoe het echt ging en waarom het ons allemaal aangaat.

Hoe het begon: gewoon een telefoontje

Ergens in de eerste week van februari 2026 nam een medewerker van Odido's klantcontactafdeling de telefoon op. Aan de lijn was iemand die zich voordeed als IT-support, vriendelijk, professioneel en met genoeg technisch jargon om geloofwaardig te klinken. Of het één medewerker was of meerdere is publiekelijk niet bevestigd maar de methode is duidelijk: vishing (voice phishing), gecombineerd met een phishingmail die al eerder was verstuurd.

De aanvaller vroeg de medewerker een extra inlogverzoek te bevestigen. Door die bevestiging omzeilden de aanvallers van hackersgroep ShinyHunters zelfs de tweefactorauthenticatie (MFA) en kregen ze toegang tot het klantcontactsysteem van Odido: gebouwd op Salesforce, gevuld met de gegevens van miljoenen mensen.

De aanvallers hadden toegang tot een systeem met namen, adressen, e-mailadressen, telefoonnummers, IBAN-nummers, geboortedata, ID-documentnummers én interne klantnotities. En dat alles, ongezien en ongestoord, voor minimaal 48 uur.

Bronnen: Odido disclosure, BleepingComputer, NOS, RTL Nieuws

48 uur. Ongestoord.

Wat volgde was geen razendsnelle smash-and-grab. De aanvallers escaleerden rechten op methodische wijze, bewogen lateraal door de cloudomgeving, brachten datastores in kaart en exporteerden alles wat waarde had. Toen pas vertrokken ze en namen contact op voor losgeld.

7 februari 2026. Eerste toegang via vishing. MFA omzeild via gecompromitteerde SSO-sessie.

12 februari. Odido maakt het datalek publiek. Eerste schatting: 6,2 miljoen getroffen klanten.

24 februari. ShinyHunters eist meer dan 1 miljoen euro losgeld. Odido weigert te betalen.

26 tot 28 februari. ShinyHunters lekt dagelijks 1 miljoen rijen data. RTL ontdekt interne notities over slachtoffers van stalking en huiselijk geweld.

1 maart. ShinyHunters gooit alles online: 6,5 miljoen individuen, 600.000 bedrijven, meer dan 5 miljoen ID-documenten. Totaal geclaimd: 15 tot 21 miljoen records.

De schade die je niet in cijfers uitdrukt

De technische schade is immens, maar het werkelijk pijnlijke zat in de interne notities. Klantenservice-medewerkers van Odido hadden jarenlang zorgvuldig vastgelegd wie er gestalkt werd, wie in een beschermde woonsituatie zat, wiens adres niet gedeeld mocht worden. Die informatie lag nu voor iedereen open op het internet. Geen speciale software nodig, geen dark web-kennis vereist. Gewoon downloaden.

Speculatie, niet publiekelijk bevestigd:

Hoe konden aanvallers 48 uur lang ongestoord exporteren zonder dat alarmbellen afgingen? Vermoedelijk ontbrak actieve monitoring op ongebruikelijke bulk-exports. In grote klantcontactsystemen zijn exportmogelijkheden vaak breed toegankelijk voor servicerollen: logisch voor dagelijks gebruik, gevaarlijk zodra een account gecompromitteerd is.

Wat dit ons zegt over mensen en systemen

De Odido-hack illustreert iets ongemakkelijks: de aanval begon precies daar waar een organisatie het meeste klantcontact heeft. Niet omdat die medewerkers onoplettend waren, maar omdat ze hun werk deden. Ze namen de telefoon op, ze bevestigden een verzoek dat legitiem klonk. Dat is hoe support werkt, en dat is ook precies wat aanvallers uitbuiten.

De kwetsbaarheid zit dus niet in de mensen zelf, maar in de combinatie van menselijk vertrouwen en brede systeemtoegang. Hoe groter de toegang die nodig is om klanten goed te helpen, hoe groter de potentiële schade als die toegang in verkeerde handen valt. Dat is geen verwijt aan wie dan ook. Het is een structureel gegeven waar elke organisatie met klantcontact mee te maken heeft.

Waarom segmentatie geen IT-jargon is

De reden dat de aanvallers zoveel data konden stelen is dat het systeem enorme hoeveelheden gegevens bevatte én dat de gecompromitteerde toegang breed genoeg was om alles te exporteren. Informatie-segmentatie, het principe dat een account alleen toegang heeft tot wat strikt noodzakelijk is had de omvang drastisch kunnen beperken.

Het gaat niet om wantrouwen richting medewerkers. Het gaat om het beperken van de blast radius als er toch iets fout gaat. Want zoals Odido heeft aangetoond: er gaat altijd een keer iets fout.

Wat we meenemen

  • Social engineering begint menselijk: een mail, een telefoontje, een MFA-ping.
  • Iedereen met legitieme systeemtoegang is een potentieel doelwit. Ervaring beschermt niet.
  • Een onverwacht MFA-verzoek is een noodsignaal, geen hindernis om snel te klikken.
  • Segmentatie en minimale toegang begrenzen de schade als een aanval slaagt.
  • Reputatieschade is het hardst te repareren en het langst zichtbaar.
English

One phone call to a helpdesk employee doing their job. And then the personal data of millions of people was out in the open. Here is how it actually happened and why it concerns all of us.

How it started: just a phone call

Sometime in the first week of February 2026, an Odido customer contact employee picked up the phone. On the line was someone posing as IT support, friendly, professional and armed with enough technical jargon to sound credible. Whether it was one employee or several has not been publicly confirmed, but the method is clear: vishing (voice phishing), combined with a phishing email sent earlier to prepare the ground.

The attacker asked the employee to confirm an additional login request. That single confirmation allowed the hacking group ShinyHunters to bypass multi-factor authentication and gain access to Odido's customer contact system, built on Salesforce and filled with data on millions of people.

The attackers had access to a system containing names, addresses, email addresses, phone numbers, IBANs, dates of birth, ID document numbers and internal customer notes. All of it, unseen and uninterrupted, for at least 48 hours.

Sources: Odido disclosure, BleepingComputer, NOS, RTL Nieuws

48 hours. Undetected.

What followed was not a smash-and-grab. The attackers escalated privileges in a methodical way, moved laterally through the cloud environment, mapped data repositories and exported everything of value. Only then did they leave and contact Odido to demand a ransom.

7 February 2026. Initial access via vishing. MFA bypassed via compromised SSO session.

12 February. Odido discloses the breach. Initial estimate: 6.2 million affected customers.

24 February. ShinyHunters demands over 1 million euros in ransom. Odido refuses to pay.

26 to 28 February. ShinyHunters leaks 1 million rows of data per day. RTL discovers internal notes on stalking victims and victims of domestic abuse.

1 March. ShinyHunters dumps everything: 6.5 million individuals, 600,000 companies, over 5 million ID documents. Total claimed: 15 to 21 million records.

The damage that does not fit in a number

The technical damage was enormous, but the truly painful part was in the internal notes. For years, Odido customer service staff had carefully recorded who was being stalked, who lived in a protected situation, whose address must never be shared. That information was now accessible to anyone on the open internet. No special software needed, no dark web knowledge required. Just download.

Speculation, not publicly confirmed:

How were the attackers able to export data undisturbed for 48 hours without triggering alerts? The likely answer: no active monitoring of unusual bulk exports. In large customer contact systems, export capabilities are often broadly accessible to service roles: logical for daily operations, dangerous the moment an account is compromised.

What this tells us about people and systems

The Odido hack illustrates something uncomfortable: the attack began exactly where an organisation has the most customer contact. Not because those employees were careless, but because they were doing their jobs. They answered the phone, they confirmed a request that sounded legitimate. That is how support works, and that is precisely what attackers exploit.

The vulnerability is not in the people themselves, but in the combination of human trust and broad system access. The wider the access needed to serve customers well, the greater the potential damage if that access falls into the wrong hands. That is not a criticism of anyone. It is a structural reality that every organisation with customer-facing operations has to contend with.

Why segmentation is not just IT jargon

The reason the attackers could steal so much is that the system contained enormous amounts of data and the compromised access was broad enough to export all of it. Information segmentation, the principle that an account can only access what is strictly necessary could have drastically limited the scope.

This is not about distrust of employees. It is about limiting the blast radius when something goes wrong. And as Odido has demonstrated: something always eventually goes wrong.

Key Takeaways

  • Social engineering starts human: an email, a phone call, an MFA notification.
  • Anyone with legitimate system access is a potential target. Experience is not a shield.
  • An unexpected MFA request is an alarm signal, not something to click through quickly.
  • Segmentation and least-privilege access contain the damage when an attack succeeds.
  • Reputational damage is the hardest to repair and stays visible longest.

Wil je weten hoe segmentatie er bij jou uitziet?

Laten we vrijblijvend bespreken waar de grootste blootstelling in jouw organisatie zit.

Neem contact op