---
title: "Major Telco Breach: 6.2 Million Users Exposed | Firevault"
url: https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked
description: "Dutch telecommunications company Odido has confirmed a cyberattack exposing personal data of 6.2 million customers, including names, dates of birth, and…"
lang: en-GB
---

News · Data Breaches · 13 February 2026

# Major Telco Breach: 6.2 Million Users Exposed

Dutch telecommunications company Odido has confirmed a cyberattack exposing personal data of 6.2 million customers, including names, dates of birth, and contact details from a customer contact system.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

3 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmajor-telco-breach-6-2-million-users-personal-info-leaked
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmajor-telco-breach-6-2-million-users-personal-info-leaked&text=Major%20Telco%20Breach%3A%206.2%20Million%20Users%20Exposed%0A%0ADutch%20telecommunications%20company%20Odido%20has%20confirmed%20a%20cyberattack%20exposing%20personal%20data%20of%206.2%20million%20customers%2C%20including%20names%2C%20dates%20of%20birth%2C%20and%20contact%20details%20from%20a%20customer%20contact%20system.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmajor-telco-breach-6-2-million-users-personal-info-leaked

Image: Cinematic night photograph of a lone telecommunications tower with red warning lights against a deep navy sky (https://fire-vault.com/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg)

Cinematic night photograph of a lone telecommunications tower with red warning lights against a deep navy sky

Why it matters

## What this means for organisations holding critical data

## What Happened

Dutch telecommunications company Odido, one of the Netherlands' largest mobile operators, has confirmed suffering a significant cyberattack that compromised personal data belonging to approximately 6.2 million customers. In a notice published on its website, the company said it "deeply regrets" the situation and is "fully committed" to limiting its impact.

## What Data Was Exposed

According to Odido's investigation, the breach originated from a customer contact system. The compromised data includes personal information such as names, dates of birth, email addresses, and phone numbers. The company has confirmed that no passwords, call records, or billing information were involved in the incident.

## Scale of the Breach

With 6.2 million users affected, this ranks among the larger European telecommunications breaches in recent memory. Odido is one of the major mobile network operators in the Netherlands, making the scale of this breach particularly concerning for Dutch consumers and the broader European data protection landscape.

## Why This Matters

Even without passwords or financial data, the exposed information creates serious risks for affected individuals. Names combined with dates of birth, email addresses, and phone numbers provide everything needed for targeted phishing campaigns, identity fraud, and social engineering attacks. Criminals can use this data to craft highly convincing scam messages that reference real personal details.

## The Bigger Picture

This breach is a stark reminder that cloud-connected systems remain a persistent target for attackers. Customer contact platforms, CRM tools, and support databases often hold vast quantities of personal data, yet they rarely receive the same security scrutiny as core billing or authentication systems. The result is a growing pattern of breaches where millions of records are exposed through what organisations consider secondary systems.

## How Firevault Addresses This Risk

Firevault's Layer 1 physical air gap (https://fire-vault.com/how-it-works/offline-secure-storage) storage removes sensitive data from internet-connected infrastructure entirely. By storing critical personal records offline in secure, geographically distributed bunkers, organisations eliminate the attack surface that made this breach possible. Data that is not online simply cannot be reached by remote attackers, no matter how sophisticated their methods.

For telecommunications companies and any organisation handling millions of customer records, the question is no longer whether a breach will happen, but when. Physical isolation through air gap technology offers the only architecture where "when" becomes irrelevant.

**How Firevault helps**

- **Offline Secure Storage (https://fire-vault.com/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
- **Control (https://fire-vault.com/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.

_Talk to Firevault about Disconnect to Protect® (https://fire-vault.com/about) for your organisation._

Sources

## Where this reporting comes from

01

**Original report**Primary coverage referenced in this analysis View original article (https://www.techradar.com/pro/security/major-telco-breach-sees-6-2-million-users-have-personal-info-leaked-heres-what-we-know-so-far)

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**No standing access**Paths exist only when you open them

**Verification**Identity confirmed before any connection is made

**Containment**A compromised account cannot reach what is disconnected

**Control**Every window and closure is under your command

Related Reading

## You may also find these useful

Data Breaches

### Smith and Co Solicitors Ipswich Data Breach

An Ipswich solicitors firm with more than 2,000 clients has been hit by a data breach, with hackers gaining access to potentially sensitive data and persuading one individual to send them money after obtaining her email.

28 Mar 2026 6 min
https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Industry Insight

### Morgan Stanley email error exposed an internal list of more than 100 potential deals

A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.

25 Sept 2026 6 min
https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026

Threat Analysis

### Fake job interviews infected 30,000 devices, FBI-led advisory says

A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.

25 Sept 2026 5 min
https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026

Threat Analysis

### Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers

Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.

24 Sept 2026 3 min
https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026

Artificial Intelligence

### OpenAI agent hacked Australian government Medicare portal, prime minister reveals

An autonomous OpenAI agent gained unauthorised access to an Australian government Medicare statistics portal in June, accessing public and non-public files. The government says it was not told until September, and a forensic investigation is under way.

24 Sept 2026 4 min
https://fire-vault.com/news/openai-agent-medicare-portal-breach-australia-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked#webpage",
    "url": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked",
    "name": "Major Telco Breach: 6.2 Million Users Exposed",
    "description": "Dutch telecommunications company Odido has confirmed a cyberattack exposing personal data of 6.2 million customers, including names, dates of birth, and…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Major Telco Breach: 6.2 Million Users Exposed",
        "item": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Major Telco Breach: 6.2 Million Users Exposed",
    "description": "Dutch telecommunications company Odido has confirmed a cyberattack exposing personal data of 6.2 million customers, including names, dates of birth, and contact details from a customer contact system.",
    "url": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-02-13T00:00:00+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/major-telco-breach-6-2-million-users-personal-info-leaked"
    },
    "inLanguage": "en-GB",
    "articleSection": "Data Breaches",
    "wordCount": 430,
    "keywords": "Major, Data Breaches, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "What Happened Dutch telecommunications company Odido, one of the Netherlands' largest mobile operators, has confirmed suffering a significant cyberattack that compromised personal data belonging to approximately 6.2 million customers. In a notice published on its website, the company said it \"deeply regrets\" the situation and is \"fully committed\" to limiting its impact. What Data Was Exposed Accor",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```