Blog Main Image
October 6, 2026

The Phone Call That Opened Six Million Customer Records

A customer service adviser at a Dutch telecoms provider took a phone call from someone who sounded like a colleague in IT. There was a ticket that needed sorting, the caller said, and he would send a link. Soon afterwards, the records of 6.2 million customers were within an attacker's reach. The Dutch police have now reconstructed the call, and it makes uncomfortable reading for any organisation with a contact centre.

In short: in February 2026, Odido, one of the Netherlands' largest mobile operators, had customer data stolen after a caller posing as internal IT persuaded a customer service employee to enter her username, password and a verification code on a fake Odido login page. No software flaw was involved. The attack worked because the request sounded like a normal workday.

What happened at Odido?

According to BleepingComputer's reporting, the breach took place on 7 February 2026 and Odido disclosed it on 12 February. The company says the affected records may include full names, addresses, mobile numbers, customer numbers, email addresses, IBANs, dates of birth and identification details such as passport or driving licence numbers. Odido has said that call details, location data, billing data, scans of identity documents and Mijn Odido account passwords were not part of the data. BleepingComputer also reports that an archive of more than 15 million records was later published online.

In September, the Dutch police went unusually public about how it started. In an appeal on the programme Opsporing Verzocht, they reconstructed the call and released a recording of the caller's voice, asking the public to help identify him.

How did the call work?

The reconstruction describes a caller who rang a customer service adviser during a normal working day and said there was a problem to be solved. He used the vocabulary of the job: open cases, open tickets, supervisors. That language did a lot of the work. It told the adviser he knew how her team operated, which made the request feel routine.

He then sent a link. It led to a fake Odido login page. The adviser typed in her username and password, and when the page asked for a verification code, she supplied that too. With those three pieces, the attackers had access to internal systems, and, as The Record reports, a customer contact system let them download customer records.

It is worth stressing what was missing. There was no malware, no exploit and, as one write-up of the case put it, no AI: just a telephone and an old-school phishing page.

Diagram of the Odido call as four exchanges between the caller and the customer service adviser, with the points where a pause could have broken the chain

Why didn't the verification code stop it?

This is the part that surprises people. The adviser did have a second factor, and she used it. The problem is what kind of second factor it was. A one-time code proves that someone has the code. It does not prove that the person typing it into a page is typing it into the real page.

When a fake login page collects a username and password, the attacker can enter them into the genuine login at the same moment. The genuine system then asks for a code, the fake page asks the adviser for the same code, and she reads it from her device. The code is valid, the login succeeds, and the attacker is in. The multi-factor step did exactly what it was designed to do. The person on the phone had simply been talked into handing it over.

That is why phishing-resistant sign-in methods, such as passkeys and hardware security keys, are widely recommended for the accounts that matter most. These are bound to the genuine website, so they will not work on a look-alike page, however convincing the phone call that sent someone there.

What is confirmed, and what is not?

Confirmed by the police and the company: the breach happened in February 2026, it affected more than six million customers, and it began with a call to customer service from a Dutch-speaking man posing as an IT colleague.

Reported but not established: the police say they have "strong indications" that Dutch hackers were involved, and the investigation is continuing. The extortion group ShinyHunters claimed responsibility on its leak site, but Odido has not officially attributed the incident to any group. We have not attributed it either, and the details of who made the call remain an open police matter.

Why are customer support teams such a good target?

Contact centre staff have a combination that attackers value. They hold broad access to customer data, they take calls from strangers all day, and they are measured on resolving issues quickly. A request from "IT" with a plausible ticket number fits neatly into that rhythm. Refusing it feels like being unhelpful.

None of that is a flaw in the individual. The adviser did what the job usually asks of her: she helped a colleague. The weakness sat in the process, which let one phone call lead to a login on a page nobody had verified. Treating this as a person who failed misses the point, and it discourages the honest reporting that catches these incidents early.

What can organisations do?

The fixes are mostly about giving people a safe way to say no, and making the safe way the easy way.

  • Set a call-back rule. Internal requests for credentials, codes or system access are verified by ringing the requester back on a number from the internal directory, never one supplied during the call.
  • Make a plain statement. IT will never ask anyone to enter a password or verification code on a page reached through a link sent during a call. Put it in writing and repeat it.
  • Use phishing-resistant sign-in for staff with broad data access. Contact centre, finance and IT admin accounts are the priority.
  • Limit what one login can reach. A single adviser account should not be able to export millions of records. Rate limits, export alerts and role-based access shrink the damage if a login is lost.
  • Practise the phone, not only the inbox. Run realistic voice and multi-channel scenarios, so staff have rehearsed saying "I'll call you back" before it matters.
  • Make reporting easy and blame-free. A quick "I think I just entered my details somewhere odd" gives the security team minutes instead of days.

The bottom line

The Odido incident is a useful reminder that phishing is not only an email problem. A phone call can create the urgency and trust that a message struggles to build, and a one-time code does not protect someone who has been persuaded to hand it over. The strongest defence is a combination: sign-in methods that cannot be relayed, limits on what any one account can reach, and a workplace where pausing to verify a caller is the expected behaviour, not an awkward one.

Sources

BleepingComputer: Police suspects Dutch hackers were involved in Odido breach. The Record: Dutch police trace Odido telco cyberattack to suspected local accomplice. Klantcontact.nl: Opsporing Verzocht reconstructs the Odido hack via customer service. This Week in Security: How a phone call allowed a hacker to steal millions of people's personal data.

Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.

Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Scroll To Top Arrow