Phishing Attack on Odido Exposes Personal Data of 6.2 Million Dutch Telecom Customers
What Happened — In February 2026, the cyber‑crime group ShinyHunters used a phishing campaign to gain access to Odido’s customer‑contact system. The attackers exfiltrated personal information—names, addresses, phone numbers, email addresses, bank details, dates of birth and passport/ID numbers—from more than 6 million accounts. Odido publicly confirmed the breach and engaged external experts to contain the incident.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a SOC 2 CC6.1 (Security Awareness) failure: employees fell for a phishing lure, allowing unauthorized access to sensitive PII.
- Continuous monitoring of phishing‑simulation results and documented training records are essential audit evidence that the “Security” principle is being enforced.
- Mapping this breach to your SOC 2 control set highlights gaps in user‑awareness programs and demonstrates the need for verifiable, repeatable security‑awareness training.
Who Is Affected – Telecommunications operators, mobile‑network providers, and any organization that stores large volumes of customer PII.
Recommended Actions
- Conduct a gap analysis against SOC 2 CC6.1, documenting current awareness training policies and frequency.
- Deploy phishing‑simulation campaigns and capture metrics (click‑through rates, remediation time) as continuous evidence.
- Update incident‑response playbooks to include rapid isolation of compromised accounts and mandatory user‑re‑education.
Technical Notes – The breach originated from a successful phishing email that delivered credentials to the attacker, who then accessed Odido’s customer‑contact database. No passwords, call logs, or billing records were taken. Source: Security Affairs