Skip to content
>_ITDITDWeb Security Platform

Security Guides

Your ID number leaked — you still don't need a new passport: what the Odido data breach in the Netherlands shows

Dutch operator Odido disclosed a customer data breach on February 12, 2026 (about 6.2 million accounts), including IBANs and passport or driver's licence numbers. What customers should and shouldn't do, per Odido and Dutch authorities.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 13 min read

For: current and former Odido and Ben customers, and anyone worried after learning that their ID number has leaked. This article is based on Odido's official disclosure and FAQ and guidance from the Dutch Central Identity Fraud Reporting Centre (CMI), the Dutch police and the Dutch Banking Association. It does not cover attack methods.

What customers should do today

1

Use the type of notice you received to see what leaked about you

Odido says it emailed affected customers from info@mail.odido.nl and sent an SMS to customers without an email address. There were four versions of the email depending on which data was involved, so the version you got tells you your situation (see the figure below). If nothing is in your inbox or spam folder, Odido says you can assume you were not affected. The Dutch police's Checkjehack tool lets you check whether your email address appears in the stolen dataset.

2

Hang up on callers claiming to be Odido, your bank or the government, then call back

Together, the leaked fields make convincing impersonation of Odido, banks or government agencies possible. Odido's advice is concrete: if an unknown number calls, ask for the caller's full name and the company's general number, say you want to verify first, and hang up. Check the number on the company's official website, then call back yourself and ask for that employee. To check whether Odido is really calling, use "Check je Gesprek" in the Odido app, which confirms whether Odido is calling you at that moment. Never give anyone your password or PIN.

3

Ignore message links and 'please change your password' requests

Odido states that it never sends messages asking you to change your password. No passwords were in the leaked data, so any "because of the breach, reset your password here" message with a link deserves suspicion. Watch for fake invoices too; check Odido bills yourself in Mijn Odido (see what is phishing?).

4

Check bank statements regularly and reverse direct debits you don't recognize

According to the Dutch Banking Association (NVB), an account number cannot be used to log in to your banking app or online banking. It can, however, be misused for unauthorized direct debits (incasso). Check statements regularly and contact your bank about debits or subscriptions you didn't sign up for. The NVB says direct debits can be reversed unconditionally within 8 weeks, and unauthorized ones within 13 months, through your bank.

5

Don't rush to replace your passport, licence or account number

Odido says that, based on current information, replacing ID documents is not necessary, in line with CMI advice (and it does not reimburse replacement costs). The NVB likewise says changing your account number is not necessary for most people. Keeping up steps 2 to 4 does more than a rushed replacement.

6

If fraud actually happens: company, police, CMI

If you find contracts or charges in your name that you don't recognize, follow the Dutch police and CMI guidance: contact the company where the fraud took place, file a police report (aangifte), and report it to the CMI (Centraal Meldpunt Identiteitsfraude). The CMI is a government service that advises and supports victims and coordinates with the police and other agencies.

7

Former customers: request deletion of your data

Odido says it keeps the contact details of customers who have left for another provider for up to 2 years (counted from when any unpaid bills or open service questions were settled). If you no longer need an account, you can request deletion through the form on Odido's website. Odido also says it offered customers facing unwanted calls the option to change their phone number.

① Name and address details

→ Beware of contacts posing as Odido, banks or agencies. Hang up and call back

② Name/address + bank details (IBAN)

→ ① plus: check direct debits on your statements regularly

③ Name/address + ID number

→ ① plus: distrust contacts that quote your ID number to seem legitimate

④ Name/address + ID number + bank details

→ All of ①–③. If fraud occurs: company, police, CMI

In every version: no passwords, call records, location data or ID scans (per Odido)

Odido sent four versions of its notice email. The version you received determines what leaked about you and which contacts to be most wary of (versions as described by Odido).

What happened (from Odido and Dutch authorities)

The following is taken from Odido's press release, information page and FAQ, and from publications by the Dutch police and the CMI.

  1. February 5–6, 2026

    The days Odido says it was hit by the cyberattack.
  2. February 7–8 (weekend)

    Odido receives the first signals of a data breach and starts investigating with internal and external experts.
  3. February 12

    Odido discloses the breach, says unauthorized access has been ended, and reports it to the Dutch Data Protection Authority (AP). It says notifying everyone may take up to 48 hours. Its spokesperson tells NOS it concerns about 6.2 million accounts.
  4. February

    The CMI publishes advice on what can and cannot be done with the leaked data, on the website of RvIG (the government's identity data agency).
  5. March 1–2

    The Dutch police say they obtained the stolen dataset and made it checkable in Checkjehack. The police say the attackers published the stolen data on their website.
  6. Later

    Odido's FAQ updates the number affected to about 6.39 million people, and says that, following clear and consistent guidance from authorities, it did not pay the ransom.
~6.2M
Accounts cited by the spokesperson at disclosure
~6.39M
People affected per the later FAQ (current and former Odido and Ben customers)
4
Versions of the notice email, by combination of leaked data
Not included
Passwords, call records, location data, ID scans
What leaked and what didn't (per Odido)
May include (differs per person)
Full name, address and city, mobile number, customer number, email address, IBAN (bank account number), date of birth, identification details (passport or driver's licence number and validity). The later FAQ also lists nationality and gender, and says that in limited cases additional information shared with customer service may be affected
Not included
Mijn Odido passwords, call details (who you called and when), location data, billing data, scans of identity documents. Odido says it does not store BSN (citizen service) numbers
The “password_c” field
Odido says the leaked field of that name was a code word used as an extra security question on phone calls, not a login password. Once it learned code words were included, it stopped phone verification based on them
Brands
Odido and Ben customers were affected; Simpel customers were not. End-user details of business customers were not leaked
Cause (Odido's account)
Criminals gained access to the customer contact system and downloaded customer data without authorization. Odido says the attacker contacted customer service posing as a member of its IT staff
Odido's response
Blocked the unauthorized access, added security measures, scaled up monitoring, raised staff awareness of phishing. Working with external experts, including a full review of data retention policies

How to read it: 'the number alone can't open a contract' is not a guarantee

The CMI says the leaked data alone cannot be used for a loan or a new bank account, because extra checks such as the physical ID document, DigiD (the government login) or bank login details are required. It also writes that it cannot guarantee every company always asks for those checks. That's why checking your statements and knowing where to report fraud are more realistic defenses than replacing documents.

ID numbers collected for verification leak from the collector

Odido explains that when you take out a mobile subscription it verifies your identity and records your ID document number to prevent fraudulent contracts. For handset financing, it says it is legally required to keep that number for up to 5 years after the credit ends. In other words, the numbers were collected to prevent fraud. Yet when the place holding them leaks, millions of them leave at once.

A Japanese counterpart: Times Car (September 2026)

  • Images of driver's licences and other ID leaked (about 1.6 million)
  • Face photo, name and address on one image
  • In Japan, a credit-bureau fraud alert is the main defense

This incident: Odido (February 2026)

  • ID numbers and expiry dates leaked (no images)
  • Authorities say the number alone cannot open a contract
  • Defense centers on checking statements and doubting impersonators

The Japanese counterpart to this case is the Times Car breach. There it was images; here it is numbers. The weight differs, but the pattern is the same: what you handed over to prove who you are leaked from the place you handed it to.

This site's view: what you can choose is where, what, and for how long

Individuals handing over ID have limited control, but not none. The Dutch government recommends using the KopieID app when you must give someone a copy of your ID: strike out the BSN or photo, and watermark the copy with who it's for and why, so a leaked copy is harder to reuse for anything else.

The lesson for collectors (service operators) is sharper: keep the result of the check ("verified"), not the number used for it; for anything the law requires you to keep, delete it automatically when the retention period ends; and limit who can see ID numbers in daily work, and how many, to what the job needs. Odido itself says most of the affected data was used for everyday sales and customer-service work, and that it is conducting a full critical review of its data retention policies and processes. The principles are covered in the minimum security baseline for organizations.

For another overseas case this year, where the problem is contact from someone who knows your booking, see the Booking.com reservation data access.

Sources (public record)

The facts in this article are based on the public information below. Attacker claims and undisclosed figures are not used.

  • Odido, "Odido informs customers of cyber attack" (press release, February 12, 2026) — newsroom.odido.nl
  • Odido information page and FAQ (Dutch and English, current version) — odido.nl/veiligheid / odido.nl/veiligheid-eng
  • Odido information page (English, version updated February 23, 2026: data involved, four notice versions, retention of former customers' data, reasons for storing ID numbers; Internet Archive copy) — web.archive.org
  • NOS, "Hack bij Odido, gegevens miljoenen klanten in handen van criminelen" (February 12, 2026: spokesperson on about 6.2 million accounts, Dutch) — nos.nl
  • RvIG / Centraal Meldpunt Identiteitsfraude, "Datalek Odido veroorzaakt ongerustheid – CMI geeft advies" (Dutch) — rvig.nl / CMI service page — rvig.nl/cmi
  • Dutch police, "Checkjehack aangevuld met Odido" (March 2, 2026, Dutch) — politie.nl
  • Dutch Banking Association (NVB), "Datalek Odido" (Dutch) — nvb.nl
  • Government of the Netherlands, identity fraud and the KopieID app (Dutch) — rijksoverheid.nl / KopieID

Update history

2026-09-30: First version, based on Odido's February 12, 2026 disclosure and information pages (the February 23 version and the current FAQ: about 6.39 million people affected, nationality and gender added, ransom not paid), and guidance from the CMI, police and NVB.

FAQ

QWhat was leaked in the Odido breach?
A

According to Odido, the data differs per person and may include full name, address and city, mobile number, customer number, email address, IBAN (bank account number), date of birth, and identification details (passport or driver's licence number and validity). Odido's later, updated FAQ also lists nationality and gender. Mijn Odido passwords, call details, location data, billing data and scans of identity documents were not included.

QHow many people were affected?
A

At disclosure on February 12, 2026, an Odido spokesperson told Dutch broadcaster NOS that criminals had access to a file with data on about 6.2 million accounts. Odido's later FAQ says about 6.39 million people were affected (current and former customers of Odido and Ben); most were notified in the initial round, and a small group received notices later.

QShould I replace my passport or driver's licence?
A

Odido says replacing an ID document is not necessary based on current information and that it follows the advice of the Dutch government's Central Identity Fraud Reporting Centre (CMI). The CMI says this data alone cannot be used to take out a loan, open a bank account or sign a phone contract, or to apply for a new ID document; extra checks such as the physical document, DigiD or bank login details are needed. It also says it cannot guarantee that every company always asks for those checks.

QMy IBAN leaked. Should I change bank accounts?
A

The Dutch Banking Association (NVB) says an account number cannot be used to log in to your banking app or online banking, and that for most people changing the account number is not necessary. It does warn about unauthorized direct debits (incasso): check your statements regularly. Direct debits can be reversed unconditionally within 8 weeks, and unauthorized ones within 13 months, through your bank.

QHow do I know whether I'm affected?
A

Odido says it emailed affected customers from info@mail.odido.nl, and sent an SMS to those without an email address. Check your spam folder; if nothing is there, Odido says you can assume you were not affected. There were four versions of the email depending on which data was involved. Since March 2026 the Dutch police's Checkjehack tool also lets you check whether your email address is in the stolen dataset.

QWhat if I become a victim of identity fraud?
A

Following the Dutch police and CMI guidance: contact the company where the fraud took place, file a police report (aangifte), and report it to the CMI. The CMI provides advice and support to victims and mediates with partners such as the police, the RDW (vehicle and licence registry) and the tax authority.

QWhat caused it?
A

Odido says criminals gained access to its customer contact system and downloaded customer data without authorization. Its later FAQ says the attacker contacted customer service posing as a member of Odido's IT staff. Odido says it has worked with external experts and implemented additional security measures.