Latest / Tech Talks With Kinsoft / Odido Data Breach – 6.2 Million Customers Exposed
Transcript
- 0:00Usually when we talk about a massive corporate
- 0:01cyber attack, there's this expectation of immediate
- 0:05visible chaos. Oh yeah, you picture the movie
- 0:08Bank Robbery, right? Exactly. Like alarms blaring,
- 0:11servers locking down, screens turning red with,
- 0:15I don't know, some ominous skull logo. Right,
- 0:17and the company instantly panicking because someone
- 0:19has loudly kicked the digital door in. Yeah,
- 0:21but what about that silent heist? You know, where
- 0:23the burglar walks right through the front door,
- 0:25waves at the security guard, and just completely
- 0:27empties the vault. And the bank doesn't even
- 0:29know they've been robbed until the thief politely
- 0:32calls them a few days later to ask for a payoff.
- 0:34Which is wildly exactly what just happened to
- 0:376 .2 million customers of the Dutch telecom Odido.
- 0:41It really is. I mean, the modern threat landscape
- 0:43has shifted dramatically away from operational
- 0:46disruption and it's moved toward quiet extraction.
- 0:49So the technical alarms never even trip because,
- 0:51well, the attackers don't actually break the
- 0:54system. No, they don't. They just log in, they
- 0:56take what they want and they leave without a
- 0:57trace. Welcome to Tech Talks with Kinsoft. Whether
- 1:01you are a seasoned tech professional catching
- 1:03up on industry news, or you are just intensely
- 1:07curious about how the digital world actually
- 1:09works behind the scenes, you're in the exact
- 1:11right place. We are super glad to have you with
- 1:14us today. Today we are analyzing a major rapidly
- 1:17developing story out of Europe, and we're going
- 1:19to do it without overwhelming you with jargon.
- 1:22We are looking at a colossal data breach at Odido.
- 1:26The mobile phone carrier, formerly known as T
- 1:28-Mobile Netherlands. And based on recent reporting
- 1:31in Security Week and other sources, this is a
- 1:33big one. It really is. So our mission today is
- 1:36to unpack the timeline of this attack, rigorously
- 1:39analyze the exact nature of the compromised data,
- 1:41and explore this really unusual silence from
- 1:45the threat actors involved. Yeah, because the
- 1:47timeline and the target selection here provide
- 1:49this... this masterclass and how modern threat
- 1:52actors operate, we really aren't looking at a
- 1:54brute force attack on a core database here. Right.
- 1:56We are looking at a highly targeted strike on
- 1:59the human element of the organization. But before
- 2:02we detail what was stolen, we need to establish
- 2:05the sheer scale of the incident. Definitely.
- 2:07Because it really explains why this specific
- 2:09breach demands your attention. So the attack
- 2:12occurred recently, specifically over the weekend
- 2:15of February 7th and 8th, 2026. And it impacted
- 2:18customers of both the primary Odido brand and
- 2:21its subsidiary, Ben. Yeah, and the initial company
- 2:24notice stated over 6 million customers were impacted.
- 2:27But a company representative reportedly told
- 2:30local media that the number is actually roughly
- 2:326 .2 million. Which is just a staggering footprint.
- 2:35Okay, let's unpack this for a second. I mean,
- 2:376 .2 million people is essentially more than
- 2:40a third of the entire population of the Netherlands.
- 2:42Wow. Yeah, that puts it into perspective. It's
- 2:45like a bad weather system that somehow managed
- 2:47to rain on almost half the country's digital
- 2:49front porches at exactly the same time. If you
- 2:51walk onto a commuter train in Amsterdam tomorrow,
- 2:54statistically, one in every three people sitting
- 2:57in that car just had their foundational identity
- 3:00documents stolen. And what's fascinating here
- 3:02is that this massive footprint is a direct result
- 3:05of where the attackers aimed. They didn't compromise
- 3:08the core telecommunications infrastructure. So
- 3:11the cell towers and routing switches are fine.
- 3:13Exactly. The core network backbone, all of that
- 3:16remained completely untouched. Instead, they
- 3:18hit a customer contact system. A customer contact
- 3:21system. Okay. Why that specific target? Well,
- 3:25when threat actors target a customer service
- 3:27silo, it yields a very specific, very concentrated
- 3:30data set. Customer service reps need immediate
- 3:33access to comprehensive user profiles, right?
- 3:36Right, to verify who they're talking to and fix
- 3:39issues quickly. Exactly. That system is inherently
- 3:41designed for fast data retrieval, which makes
- 3:44it an absolute goldmine if an unauthorized user
- 3:47gains access. So if they have unhindered access
- 3:49to this specific silo, how do they actually get
- 3:52in? I mean, you'd assume a telecom giant operating
- 3:55at a national scale would have massive digital
- 3:57wall. You would think so, yeah. We're talking
- 3:59zero trust architectures, strict multi -factor
- 4:02authentication, robust endpoint detection. Sure,
- 4:04but technology can only protect you up to the
- 4:07point where an authorized human overrides it.
- 4:10Reports allege that the attackers in this incident
- 4:12are linked to the notorious group Shiny Hunters.
- 4:15Oh, wow. Shiny hunters. Yeah. And they didn't
- 4:18burn a highly sophisticated multimillion dollar
- 4:21zero day exploit to break through Odido's firewalls.
- 4:24They just use social engineering. So they bypassed
- 4:27the technological tech entirely by manipulating
- 4:30the people who manage it. Precisely. Specifically,
- 4:33they utilized phishing and they actually impersonated
- 4:36internal IT staff to bypass the multi -factor
- 4:39authentication. That is wild. We spend millions
- 4:42on these complex security architectures. But
- 4:45if an attacker just calls the help desk, sounds
- 4:47confident, and convincingly asks for an MFA reset.
- 4:50The walls come tumbling down. It really highlights
- 4:52the vulnerability of the human firewall. It does,
- 4:55because help desks and customer support centers
- 4:57are, by definition, structurally designed to
- 4:59be helpful. Right. Their whole job is to fix
- 5:01things fast. Yeah. Their primary performance
- 5:04metric is usually how quickly they can resolve
- 5:06an internal issue and get an employee back to
- 5:09work. And threat actors absolutely. know this.
- 5:11So how does that call actually play out? Well,
- 5:14an attacker impersonating IT might call an employee.
- 5:18claim there is, say, a critical synchronization
- 5:21error on their account, and send a fraudulent
- 5:24MFA prompt under the guise of testing the connection.
- 5:28And the employee, just assuming they're interacting
- 5:30with a colleague trying to fix a problem, they
- 5:32approve the prompt. Exactly. The technology functioned
- 5:36perfectly. It verified the prompt was approved,
- 5:38but the human context was entirely fraudulent.
- 5:41And once inside... The attacker essentially inherits
- 5:45the legitimate privileges of that compromised
- 5:47employee. They sure do. Which brings us to the
- 5:49actual payload, because once they were inside
- 5:52that customer contact system, they had access
- 5:54to a very specific inventory of data. A very
- 5:57dangerous inventory. According to the disclosure,
- 6:00the hacker stole an incredibly detailed list
- 6:02of personal information. We are talking names,
- 6:06home addresses, phone numbers, email addresses,
- 6:09dates of birth, customer numbers, bank account
- 6:12numbers. And crucially, this is the really bad
- 6:14part. Yeah, the linchpin of the whole disaster
- 6:16passport or driver's license numbers, along with
- 6:19their exact validity dates. That combination
- 6:21of data points represents a complete self -contained
- 6:24identity package. It is far more dangerous than,
- 6:27you know, a simple database dump of emails and
- 6:30passwords. Well, let's look at what the company
- 6:32noted they didn't get. phone services themselves
- 6:35were not impacted. And importantly, no user passwords
- 6:38were stolen. Right. No call records, no text
- 6:41message logs, and no invoice or billing data
- 6:44were compromised. Odito really emphasized this
- 6:47point. Of course they did. It sounds like good
- 6:48news. But here's where it gets really interesting.
- 6:50They bypassed the highly sensitive call logs
- 6:53and passwords, but grabbed all the foundational
- 6:56identity documents. It's like a burglar sneaking
- 6:58into your house, completely ignoring your diary
- 7:01and your keys, but running off with your filing.
- 7:03cabinet and your bank statements. That is a perfect
- 7:06analogy. So I have to ask, does the fact that
- 7:09passwords weren't taken make this less severe?
- 7:12Or is the ID data actually a bigger nightmare
- 7:14for these 6 .2 million people? Oh, the loss of
- 7:18the ID data is unequivocally the larger disaster.
- 7:21Think about it. Passwords are inherently transient.
- 7:25Right. They're meant to be changed. Exactly.
- 7:27They are dynamic security controls designed to
- 7:30be discarded. If a database of passwords leaks
- 7:32today, the company just forces a mandatory global
- 7:36reset. You type in a new string of characters
- 7:38and the stolen data becomes entirely worthless
- 7:40to the attacker in a matter of seconds. Right.
- 7:43It really is like changing the locks on your
- 7:44front door. But the data stolen from Odido, your
- 7:47date of birth, your national identity number,
- 7:49your passport number, the validity dates of those
- 7:51documents, your bank account details. These are
- 7:54completely static. You can't exactly just update
- 7:57your date of birth. No, you can't. They are the
- 7:59foundational anchors of your societal identity.
- 8:03You cannot simply log into a government portal
- 8:05and click reset on your passport history. Replacing
- 8:08a government ID is a massive bureaucratic headache.
- 8:11You have to physically go to an office, prove
- 8:14who you are all over again, pay fees, and wait
- 8:17weeks. And even then, your historical data is
- 8:20still intrinsically tied to you. But are they
- 8:23going to use these passports to open fraudulent
- 8:25credit cards? Or is there a bigger secondary
- 8:27market for this? Because a passport number alone
- 8:30without the physical book doesn't get you through
- 8:33airport security. Well, they don't need to get
- 8:36through an airport. They need to get through
- 8:37automated digital verification systems. the financial
- 8:41sector relies heavily on know your customer or
- 8:44kyc regulations when you open an account at an
- 8:47online bank a cryptocurrency exchange or a brokerage
- 8:51the institution doesn't see you in person. Right.
- 8:53They rely on cross -referencing the data you
- 8:55provide against government and credit databases.
- 8:58Exactly. So if an attacker has your real name,
- 9:01address, date of birth, bank account number,
- 9:03and the exact validity dates of your passport,
- 9:07they possess the perfect recipe to defeat modern
- 9:10KYC algorithms. Wow. So they aren't just stealing
- 9:14your identity, they're essentially cloning it.
- 9:16They can spin up an entirely parallel digital
- 9:18life. That is the ultimate goal. With a complete
- 9:21package, which is often referred to on the dark
- 9:24web as fool's a malicious actor, doesn't bother
- 9:27trying to hack into your existing Odido account
- 9:29or your current checking account. Because that
- 9:32carries too much risk of triggering an alert.
- 9:34Exactly. Instead, they go to a completely different
- 9:37financial institution and open a brand new account
- 9:39in your name. They apply for high yield loans.
- 9:42They establish lines of credit. They use your
- 9:44pristine financial history to extract cash. And
- 9:47you remain completely unaware. until the collection
- 9:49agencies start calling months later. Yep. Untangling
- 9:52that type of synthetic identity fraud requires
- 9:55hundreds of hours of legal wrangling, and it
- 9:57can ruin a person's credit standing for years.
- 10:00So while Odido is technically accurate in reassuring
- 10:03people that their account passwords are safe,
- 10:06the attackers walked away with an asset that
- 10:08is infinitely more valuable and permanent. Without
- 10:10a doubt. That terrifying asymmetry in data value
- 10:13makes the company's response and the broader
- 10:16aftermath of this incident really critical to
- 10:19analyze. Yeah. Let's look at the immediate containment.
- 10:22Okay. Odido states that they immediately closed
- 10:25the attackers' access to their systems, implemented
- 10:28additional security measures, and notified the
- 10:31relevant regulatory and law enforcement authorities.
- 10:33Which is standard, yeah. Right. And they're actively
- 10:36notifying the affected users via email or phone,
- 10:39warning them to be on high alert for phishing
- 10:42attempts. They've also partnered with cybersecurity
- 10:44experts to monitor the dark web. And what have
- 10:47they found so far? Well, as of the reporting,
- 10:50they are currently not aware of the stolen information
- 10:52being published online. And that right there,
- 10:55the absence of that data on the dark web, is
- 10:57the pivot point of the entire narrative. What
- 11:00do you mean? It tells us exactly what kind of
- 11:02operation we are observing. If we connect this
- 11:04to the bigger picture, it explains a lot. Because
- 11:07that's the mystery of the missing threat actor.
- 11:09Right. Odito hasn't officially shared details
- 11:12on the threat actor in their public notice. And
- 11:15no known ransomware or extortion group appears
- 11:18to have publicly claimed responsibility for it
- 11:21on their leak sites. Which is very unusual for
- 11:23a typical ransomware group. Yeah. But reports
- 11:26allege that Odito only actually learned of the
- 11:29massive data theft when the attackers contacted
- 11:32them directly to launch an extortion attempt.
- 11:35Exactly. So what does this all mean? They bypass
- 11:38the alarms. steal the data quietly, and then
- 11:41basically call the CEO. Usually, we hear about
- 11:44ransomware groups making massive public demands.
- 11:47Right. They freeze the servers, put a countdown
- 11:49timer on a public leak site, and shame the company
- 11:52into paying. But here, the systems are running
- 11:54perfectly fine, the data isn't leaked, and there's
- 11:56just silence. So they've done math. They know
- 11:58the regulatory fines are going to be catastrophic,
- 12:00don't they? That is the exact leverage they're
- 12:03exploiting. We are witnessing a stark evolution
- 12:06in cyber extortion tactics here. How so? The
- 12:09traditional ransomware model, you know, encrypting
- 12:12computers so a company cannot do business, is
- 12:14incredibly loud. It immediately brings the full
- 12:17weight of international law enforcement down
- 12:19on the hacking group because critical infrastructure
- 12:22is disrupted. Sure, nobody can make phone calls,
- 12:24so the police get involved immediately. Right.
- 12:26But the new model, which we see allegedly utilized
- 12:29by groups like Shiny Hunters, is pure data extortion.
- 12:32They don't break the network. Odido's mobile
- 12:35phones kept connecting to towers just fine. The
- 12:37attackers quietly copied the database and slipped
- 12:40out the back door. Yes. So the leverage is no
- 12:43longer pay us or your business stays offline.
- 12:45The leverage is pay us or we will unleash an
- 12:48absolute regulatory and public relations catastrophe
- 12:51upon you. Let's dig into that regulatory doom,
- 12:54because if they dump 6 .2 million European citizens
- 12:58passports and bank accounts online, the legal
- 13:01fallout for the telecom company has to be astronomical.
- 13:04Oh, it is. The European regulatory environment
- 13:07is completely unforgiving when it comes to data
- 13:09protection. We're talking about GDPR, right?
- 13:11Yes. Under the General Data Protection Regulation,
- 13:14companies can face fines of up to 4 % of their
- 13:16global annual revenue for failing to adequately
- 13:19protect consumer data. Wait, 4 % of global revenue?
- 13:23That is massive. And that is just the baseline.
- 13:26You also have the Dutch Data Protection Authority
- 13:28stepping in to launch an independent investigation
- 13:31which carries its own penalties. The inevitable
- 13:34class action lawsuits from the millions of victims
- 13:36whose static identities are now permanently at
- 13:39risk. Exactly. The financial impact of the data
- 13:41becoming public easily stretches into the hundreds
- 13:43of millions of euros. So the attackers are basically
- 13:46presenting a twisted business proposition. They're
- 13:49saying, we know a breach of this magnitude will
- 13:51cost you half a billion euros in fines, lawsuits
- 13:54and brand damage. Pay us 20 million quietly and
- 13:57we delete the data. It's a bargain. It is a cold,
- 14:00calculated risk assessment forced upon the victim,
- 14:03and it entirely explains the public silence.
- 14:06The attackers do not want to publish the data
- 14:08yet. Because the threat of publication is the
- 14:11only thing giving them leverage. Exactly. If
- 14:13they dump it online out of frustration, Odito
- 14:16suddenly has absolutely no incentive to pay the
- 14:18extortion fee. The damage is already done. Right.
- 14:21So the threat actors keep it quiet, they keep
- 14:24it off the public leak sites, and they attempt
- 14:26to negotiate in the shadows. That's the play
- 14:29here. But let's play this out. What if the company
- 14:31calls their bluff? Odido refuses to pay a dime
- 14:34or the negotiations break down. Are the attackers
- 14:38just going to sit on a goldmine of 6 .2 million
- 14:40passports? If they don't dump it publicly to
- 14:43shame the company, what is the secondary play?
- 14:46Hoarding the data for private. Secondary exploitation
- 14:49is the highly probable backup plan. Meaning they
- 14:52sell it quietly. Yes. Even if the primary extortion
- 14:55against the corporation fails, this specific
- 14:58data set is incredibly valuable in the cyber
- 15:00criminal underground. They don't have to dump
- 15:03it publicly on a forum where security researchers
- 15:05can analyze it. They could just sell it piecemeal
- 15:07to other criminals. Right. They can quietly sell
- 15:09it in chunks to closed door fraud rings who specialize
- 15:12in the identity cloning we discussed earlier.
- 15:15Or even more insidiously, they can use it themselves
- 15:18to launch highly targeted secondary phishing
- 15:20campaigns against the Odido customers. Wait,
- 15:23why use a leaked database for phishing, though?
- 15:26I mean, I get spam emails every day telling me
- 15:28my streaming account is locked and I just ignore
- 15:30them. You ignore them because they are generic
- 15:32and lack context. But imagine the scenario for
- 15:35these 6 .2 million users. Okay, I'm imagining
- 15:38it. You know your data was compromised in the
- 15:40Uduto breach, right? It's national news. Two
- 15:43weeks later, you receive an email that appears
- 15:44to be from your primary bank. And it says something
- 15:47like, we noticed suspicious activity related
- 15:49to the recent telecom breach. Exactly. Please
- 15:52click here to verify your account. But the reason
- 15:55this works is the attacker includes your actual
- 15:57real bank account number and the expiration date
- 16:00of your passport right there in the email body.
- 16:03Oh, wow. That changes the psychology entirely.
- 16:06If I see an email with my actual passport expiration
- 16:09date in it, my brain immediately assumes it has
- 16:12to be legitimate. The level of trust is established
- 16:14instantly. Exactly. The attackers leverage the
- 16:18static data stolen in the first breach to manufacture
- 16:20unquestionable trust. This lowers your guard,
- 16:23allowing them to extract the one thing they didn't
- 16:25get from Odido. Your passwords. Yes. They use
- 16:29the static data to trick you into handing over
- 16:31the dynamic data. It is a vicious, compounding
- 16:35cycle of compromise that relies entirely on the
- 16:37fact that these foundational identifiers are
- 16:39implicitly trusted by both institutions and individuals.
- 16:43It really paints a stark picture of just how
- 16:45fragile our entire digital ecosystem is. I mean,
- 16:48we trust these massive corporations with the
- 16:50foundational documents. of our lives, and one
- 16:53successful, well -crafted phone call to an IT
- 16:55help desk can expose a third of a country's population.
- 16:58It really fundamentally challenges how we think
- 17:00about security. It absolutely does. So to quickly
- 17:03recap the ground we've covered today for you,
- 17:05we analyzed the colossal data breach at Odido,
- 17:08impacting roughly 6 .2 million customers. and
- 17:11the attackers who are linked to shiny hunters
- 17:13bypass technical defenses by leveraging social
- 17:16engineering and help desk impersonation to slip
- 17:19past multi -factor authentication right they
- 17:22targeted a customer contact system completely
- 17:25ignoring changeable data like passwords and instead
- 17:28extracted an absolute gold mine of static identity
- 17:31documents passports driver's licenses And bank
- 17:35accounts. And now the entire situation is shrouded
- 17:38in an unusual silence driven by behind the scenes
- 17:42data extortion and the looming threat of massive
- 17:44regulatory and legal fallout across Europe. Which
- 17:47really is a textbook case study demonstrating
- 17:49why the cybersecurity landscape is shifting.
- 17:52Protecting the perimeter is clearly no longer
- 17:54sufficient when the human element remains the
- 17:56most critical vulnerability. And when the data
- 17:58itself has become the ultimate leverage. As we
- 18:01wrap up this discussion, we want to leave you
- 18:02with a final thought to mull over. Yeah, because
- 18:04the Odido breach forces us to confront an uncomfortable
- 18:07reality about the architecture of trust. This
- 18:11raises an important question. What happens to
- 18:13the value of our digital identities when hackers
- 18:16realize that quietly hoarding static documents
- 18:18like passports and bank numbers is far more lucrative
- 18:21than stealing easily changeable passwords? How
- 18:25do we protect something we can't easily reset?
- 18:28It's a critical question we all need to be asking
- 18:30ourselves, both as individual consumers navigating
- 18:33the digital world and as professionals architecting
- 18:36corporate infrastructure. Absolutely. If this
- 18:39story has you thinking about your own organization's
- 18:41vulnerabilities and perhaps realizing it's time
- 18:44to evaluate how you handle, segment, and protect
- 18:47sensitive data against the human element, we
- 18:49highly encourage you to visit www .kinsoft .com
- 18:53.au to discuss your own security and IT needs.
- 18:56You can't just build a taller digital wall. You
- 18:59really have to plan for what happens when someone
- 19:01just talks their way through the front door.
- 19:03Thank you so much for tuning in to Tech Talks
- 19:05with Kinsoft. Thanks for listening. Stay safe
- 19:07out there, keep a close eye on your static data,
- 19:09and we will see you next time.