Decoding the world of cybersecurity

Police reveal route into Odido breach

Dutch investigators say an attacker impersonated Odido’s IT department, captured an employee’s credentials and verification code, and gained access to data belonging to more than six million customers.

Police reveal route into Odido breach
Summary
  • Police say a Dutch-speaking attacker impersonated an internal IT employee during a call to Odido customer service.
  • The targeted employee was directed to a cloned login page and supplied credentials and a further verification code.
  • More than six million customer records were stolen and later published after Odido refused a ransom demand.

Dutch police have disclosed how criminals gained access to telecoms provider Odido before stealing data belonging to more than six million customers, describing a social-engineering attack that overcame both an employee password and an additional verification step.

An attacker called Odido customer service and impersonated a colleague from the company’s IT department, according to investigators from the Dutch National Police. The caller used enough internal terminology to convince the employee that the request was legitimate and said an internal problem needed to be resolved.

The employee was then directed to a cloned Odido login page. Police said the employee entered login details and later supplied an additional verification code, allowing the attackers into an internal system.

The disclosure provides a clearer account of the route used in one of the largest data thefts recorded in the Netherlands. Police said the attackers obtained information relating to more than six million Odido customers, demanded a ransom, and subsequently published stolen data after the telecommunications company declined to pay.

Investigators have now released an audio recording of the suspected caller as part of an appeal for information. Police say the recording contains the person’s real voice rather than AI-generated speech and describe the suspect as Dutch-speaking and familiar with technical terminology.

The attack did not require exploitation of a software vulnerability. Instead, the criminal persuaded an employee to participate in an authentication process controlled by the attacker.

The additional verification code is an important part of that sequence. Multi-factor authentication can stop an attacker who possesses only a stolen password, but authentication methods relying on temporary codes can still be defeated when a victim is persuaded to disclose the value during a live interaction.

That makes the Odido incident an identity-control failure as well as a social-engineering case. The attacker needed enough information about internal practices to appear credible, a convincing reason for the employee to authenticate, and a counterfeit login environment capable of capturing the required values.

Service desks and support functions are attractive targets because employees routinely handle account problems, access requests, and technical issues that require rapid decisions about identity. Attackers who understand an organisation’s terminology and processes can exploit that familiarity to make an unusual request appear routine.

Telecommunications providers also hold concentrated stores of identity and contact data. When customer information is stolen at this scale, the consequences can extend beyond the immediate breach because names, telephone numbers, addresses, and account-related data may improve later phishing and impersonation attempts.

The police disclosure does not establish how the attackers acquired their knowledge of Odido’s internal terminology or who ultimately controlled the operation. The identity of the caller also remains under investigation.

Those unknowns do not obscure the point at which access was obtained. According to investigators, a criminal posing as an internal IT colleague persuaded an employee to use a cloned authentication page and provide the additional information required to enter an internal system.

The case shows how authentication controls can fail when identity verification is reduced to possession of credentials and codes while the human process surrounding them is being manipulated. Odido’s breach began with a telephone conversation, but the result was access to information belonging to millions of customers.

×