Dutch police said their investigation into the cyberattack on telecom provider Odido found indications that Dutch nationals may have helped carry out the breach, which exposed personal data belonging to more than 6 million customers. Investigators from Team High Tech Crime and the Public Prosecution Service said a Dutch-speaking man allegedly impersonated an Odido IT employee in a call to customer service shortly before the February intrusion, suggesting the attackers used social engineering and phishing to gain access.
Authorities said the attackers accessed a compromised customer contact system used by Odido, downloaded customer records, and later distributed the stolen data publicly. Police have already taken multiple servers linked to the hacker group offline and are appealing for information from the public and people in cybercrime circles, while warning that the investigation is expected to continue for several more months.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Dutch police and prosecutors said their investigation found indications that Dutch nationals may have been involved in the Odido cyberattack. They said the inquiry is ongoing, are seeking information from the public and cybercrime circles, and expect the investigation to continue for months.
Shortly after the incident, Dutch police took multiple servers used by the hacker group offline. Investigators said the infrastructure had been used to distribute the stolen Odido data.
After the breach, the stolen data from more than 6 million Odido customers was publicly released. Authorities linked the released data to the February cyberattack.
Shortly before the February attack, a Dutch-speaking man allegedly called Odido customer service while posing as an IT employee. Investigators believe this social-engineering step helped employees grant the attackers access.
In early February 2026, attackers gained access to a compromised customer contact system used by Odido and downloaded customer records. The breach affected personal data belonging to more than 6 million customers.
Odido disclosed the cyberattack on February 12, 2026, after attackers accessed a customer contact system and stole customer data. The company later said about 6.2 million customers were affected.
Odido disclosed that attackers accessed its customer contact system on February 7, 2026. The company later said the breach affected 6.2 million customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcedarkwebinformer.com
Open sourcebleepingcomputer.com
Open sourcepolitie.nl
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.