Information page Odido cyber incident.

Last updated on 19 February 2026, 10.50

Why is this page?

Odido has been affected by a cyberattack, in which customer data has been impacted. This involves personal data originating from a customer contact system used by Odido. No passwords, call details, or billing data are involved.

We deeply regret this incident and are fully committed to limiting the impact of this incident and providing our customers with all necessary support. It is important to emphasize that our operational services have not been affected; customers can continue to call, use the internet, and watch TV safely.

Unauthorized access to the system was ended as quickly as possible. In addition, Odido has engaged external cybersecurity experts to support the implementation of additional security measures as part of the response to this incident.

Affected customers have received an email directly from the email address info@mail.odido.nl or an SMS from Odido. Odido has also reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).

On this page we share more information about this incident, a frequently asked questions section, and any important updates. You can also read here about steps you can take yourself, in addition to the measures Odido has already taken.

What should I do?

Be extra alert for suspicious and unusual activities. Unfortunately, cyberattacks like this are becoming increasingly common, and no organization is immune. Not every data breach leads to actual misuse, but we cannot rule out the possibility that your data may be misused.

Below are concrete situations where we ask you to be extra alert:

  • With your name, address, phone number, email address and bank account number, cybercriminals may try to contact you while pretending to be someone from Odido, your bank, or another organization. Therefore, always remain alert to these kinds of phone calls, text messages, app messages, or emails. 

  • Be careful when opening links in emails, text messages, and app messages. You can often recognize a suspicious email, text message, or app message by typos and unknown senders. Check the phone number, or what appears after the “@” sign in an email address. 

  • Do you receive an unexpected call from a number you don’t know? It may indeed be an employee of your bank or another company calling. You can verify this by asking the caller for their first and last name and asking for the company’s general phone number. If in doubt, say you would like to verify first whether the person is a real employee and hang up. Then check the company’s website to see if the number is correct. Is the number correct? Then call the company yourself and ask for the employee who called you. 

  • Never give anyone your password or PIN code. 

  • Always be alert when receiving invoices. Cybercriminals may exploit the situation by sending fake invoices that appear to come from Odido or other parties. Therefore, always carefully check the origin and accuracy of received invoices before proceeding with payment. For example, you can always view an Odido invoice in your Mijn Odido environment. If you are in doubt, always contact us. 

What information is involved?

The email we sent you is decisive for your personal situation. It states exactly what applies to you.

The information involved may include: 

  • Full name  

  • Address and city of residence  

  • Mobile number  

  • Customer number  

  • Email address  

  • IBAN (bank account number)  

  • Date of birth  

  • Identification details (passport or driver’s license number and validity)

What information is not involved?

The information involved does NOT include: 

  • Mijn Odido passwords  

  • Call details (who you called, when)  

  • Location data  

  • Billing data  

  • Scans of identity documents 

Why are we reporting this?

We always want to be transparent with our customers, and we want to inform you so you can be alert to any unusual activities. We also want to emphasize that your security is our highest priority. Because of this incident, no one can view your mobile location data or your private contacts.

How is Odido taking action?

Odido is working together with external cybersecurity experts as part of our response to this incident.

  • Security strengthened – After the discovery of the attack, unauthorized access to our system was immediately shut down. Odido immediately took additional security measures.

  • Regulation & transparency – We reported the data breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).

  • SupportWe want to help you. That’s why we have opened this special information page.

More information.

We would like to keep you informed via this web page about any important new information regarding this security incident. Our customers received a personal email or an SMS about this incident. Keep an eye on this information page in the coming period.

We understand that you may have questions. Consult this page for the most up-to-date updates. Our customer service colleagues cannot provide any additional information at this time beyond what is shared here.

Again, we deeply regret this situation and are fully committed to providing you with all necessary support.

You are our customer, and your interests come first. 

Søren Abildgaard 
CEO Odido

Frequently asked questions.

These FAQs may be updated. If you have new questions, first check out this FAQ page to see if new information is available before contacting us.

General

Identification details

Bank account number

Login details

Compensation

Details of former customers

Business

Contact