Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurebreach-disclosure-notificationunderground-data-leaktelecommunications-sector-threat

Odido Customer Data Breach and Extortion Leak Campaign

Updated 3mo agoFirst seen Mar 2, 20263 sources

Dutch telecom Odido reported that attackers stole data on 6.2 million current and former customers, while the threat actor claimed the dataset covers 8+ million people and demanded €1M+ in ransom, threatening to publish data in daily tranches if unpaid. Reporting indicates the company refused to pay, and the extortionists proceeded with a staged leak strategy intended to maximize public and media impact.

Subsequent leak batches reportedly included not only typical customer identifiers (e.g., names, addresses, phone numbers, dates of birth, bank account numbers, and ID numbers) but also internal customer-service notes containing highly sensitive context such as stalking, threats, domestic violence, and protected addresses—creating potential physical safety risks for affected individuals. The leak cadence was described as multiple dumps over consecutive days (including a “final dump”), drawing significant national attention in the Netherlands and increasing the likelihood of intensified law-enforcement focus on the perpetrators.

Share:
Odido Customer Data Breach and Extortion Leak Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 2, 20264mo ago

Final dump of all remaining Odido data is released

The day after the third release, the attackers published a final dump containing the remaining stolen Odido data. This completed the multi-stage public leak sequence described in subsequent coverage.

Mar 1, 20264mo ago

Third staged Odido data dump is released

According to later reporting, a third dump occurred a few hours after the second release. The continued cadence suggested the leak campaign was being timed for maximum public and media impact.

Feb 28, 20264mo ago

ShinyHunters threatens more Odido leaks over the next two weeks

After the second batch was reported, the threat actor ShinyHunters said it would continue releasing more Odido data over the following two weeks if payment was not made. The statement escalated pressure on Odido after the company refused the ransom demand.

Second Odido data dump exposes sensitive internal notes

A second batch of leaked Odido data was reported by Dutch media to contain highly sensitive internal customer notes, including references to stalking, threats, domestic violence, and protected addresses. Reporting said the exposed information created potential physical safety risks for affected customers.

First Odido data dump is released

The stolen Odido data began to be published in staged releases over several days. This first dump marked the start of the public leak campaign tied to the extortion attempt.

Attackers demand over €1 million and threaten staged leaks

The threat actor demanded more than €1 million from Odido and threatened to publish 1 million lines of stolen data per day if the company did not pay. Odido refused to pay the ransom.

Odido customer data is stolen in a major breach

Attackers stole customer data from Dutch telecom company Odido. Odido said the breach affected 6.2 million current and former customers, while the attackers claimed to hold data on more than 8 million people.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Threat actors
1 linked
Organizations
3 linked
OdidoNL TimesRTL
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.