ODIDO A.I CyberSecurity Scoring
ODIDO
Company Information
Website:http://www.odido.be
Employees number:27
Number of followers:208
NAICS:
Industry Type:Information Technology & Services
Homepage:odido.be
ODIDO Risk Score (AI oriented)
Between 550 and 599
ODIDOInformation Technology & Services
Updated:
08/06/2026
08/06/2026
596/1000
Very Poor
Ca
ODIDO Global Score (TPRM)
xxxx
ODIDOInformation Technology & Services
Score locked

ODIDOVery Poor
Current Score
596Ca (VERY POOR)
01000
3 incidents
-81.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
603
JULY 2026
600
JUNE 2026
596
MAY 2026
659
Breach
01 May 2026 • ODIDO
Odido: Financial administrators' poor email security put many people with money trouble at risk
Cybercriminals Exploit Poorly Secured Email Addresses of Dutch Financial Administrators
592
CRITICAL-67
ODI1780915137
Cybercriminals Exploit Poorly Secured Email Addresses of Dutch Financial Administrators
Cybercriminals are gaining unauthorized access to highly sensitive personal data by targeting abandoned email addresses of financial administrators in the Netherlands. These administrators manage the affairs of hundreds of thousands of vulnerable individuals including those with debts or intellectual disabilities handling confidential documents such as tax records, medical bills, payslips, and telecom call logs.
The vulnerability was uncovered by ethical hacker Wesley Neelen, who identified the issue while analyzing leaked Odido data. Many individuals had used their administrator’s email for billing, but the addresses were no longer active. Neelen demonstrated how easily these abandoned domains could be hijacked, registering 258 financial files within weeks including distressing details like housing reports describing a client’s severe neglect and even a death certificate.
Experts warn that the exposed data puts already vulnerable individuals at greater risk of fraud and exploitation. Professor Nadja Jungmann of Utrecht University of Applied Sciences called the leak "truly terrible," noting that debtors are more likely to fall for scams promising quick financial relief.
The problem stems from administrators failing to secure or decommission old email domains, often due to bankruptcy, mergers, or service discontinuation. While the Netherlands Internet Domain Registration Foundation (SIDN) issues warnings about expiring sensitive domains, many organizations overlook them. Aegis, the trade association for financial administrators, has pledged to alert its members and explore protocols to prevent future breaches.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
659
MARCH 2026
657
FEBRUARY 2026
755
Breach
12 Feb 2026 • ODIDO
Odido: Stolen Odido data worth “gold” for criminals
Massive Data Breach at Dutch Telecom Provider Odido Exposes 6.2 Million Accounts
659
CRITICAL-96
ODI1771093701
Massive Data Breach at Dutch Telecom Provider Odido Exposes 6.2 Million Accounts
Dutch telecom provider Odido has reported one of the largest data breaches in the Netherlands, with sensitive information from 6.2 million customer accounts compromised. The company began notifying affected users on Thursday at 12 p.m., though the exact number of impacted individuals remains unclear as the investigation continues.
The stolen data varies by account but may include full names, addresses, phone numbers, email addresses, IBAN bank account numbers, dates of birth, and passport or driver’s license numbers a combination cybersecurity experts describe as unusually valuable for criminals. Notably, passwords, call logs, location data, billing details, and ID document scans were not accessed.
Ethical hacker Sijmen Ruwhof warned that the breach poses severe risks, including highly convincing phishing attacks where criminals use real customer details to impersonate legitimate companies. Fraudsters could also exploit the data to bypass authentication checks, taking out contracts or committing financial fraud in victims’ names. Matthijs Koot, another security expert, highlighted the risk of helpdesk fraud, bank scams, and targeted espionage, noting that hostile intelligence services could use the data to track politicians, government employees, or critical infrastructure workers.
The breach also raises concerns about stalking, doxxing, and organized crime, as criminals including drug offenders could use the data to identify individuals using regular phone subscriptions. Ruwhof criticized Odido’s security measures, stating that the scale of the leak suggests a failure in cybersecurity controls at the time of the incident. While the company has not disclosed whether hackers made ransom demands, experts warn the data could be sold or used for extortion.
Odido CEO Tisha van Lammeren emphasized that notifications were delayed to avoid misinformation but did not comment on the adequacy of the company’s security. She acknowledged the sophistication of cybercriminals while reiterating that customer safety remains the top priority. The full impact of the breach is still under assessment.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
750
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
MAY 2025
755
Vulnerability
01 May 2025 • ODIDO
Salesforce and Odido: Lessons from the Odido hack: Why devious hackers are no excuse
Odido Data Breach Exposes 6 Million Customers in Major Dutch Cybersecurity Failure
747
CRITICAL-8
SALODI1772484824
Odido Data Breach Exposes 6 Million Customers in Major Dutch Cybersecurity Failure
One of the largest data breaches in recent Dutch history has left over six million Odido customers vulnerable after hackers exploited weak security processes and architectural flaws. The telecom provider initially described the attack as "sophisticated," but investigations reveal a preventable incident rooted in social engineering and poor access controls.
The breach began with a well-documented tactic: hackers impersonated IT staff over the phone to trick employees into handing over login credentials or approving unauthorized access. This method, known as social engineering, had been flagged months earlier by the FBI and Salesforce, Odido’s customer data platform. Despite these warnings, the company failed to implement adequate safeguards.
Once inside, attackers exploited a critical misconfiguration in Odido’s Salesforce environment. They linked a malicious "connected app," effectively creating a backdoor to the database. In a properly secured system, such an action would require administrator approval, but Odido’s setup allowed a single compromised account to access millions of records a violation of the "least privilege" principle, which dictates that users should only have access to data necessary for their role.
The breach highlights the dangers of outdated security models. Odido relied on the "castle wall" approach trusting users once inside the network rather than adopting modern "Zero Trust" principles, which verify every access request regardless of origin. The lack of behavioral monitoring also allowed the attackers to exfiltrate data undetected, despite red flags like unusual login times or bulk record requests.
The fallout extends beyond Odido. Stolen data, including passport numbers and bank details, enables large-scale identity fraud, eroding public trust in digital services. The incident underscores the need for data minimization companies should not collect or store sensitive information unless absolutely necessary. While Odido has not paid a ransom, the societal cost of compromised privacy continues to mount.
The breach serves as a stark reminder that cybersecurity failures are rarely about hacker sophistication but about preventable lapses in process, architecture, and vigilance.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ODIDO ??
What was ODIDO's A.I Rankiteo Cyber Score in July 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in June 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in May 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in April 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in March 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in February 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in January 2026 ??
What was ODIDO's A.I Rankiteo Cyber Score in December 2025 ??
What was ODIDO's A.I Rankiteo Cyber Score in November 2025 ??
What was ODIDO's A.I Rankiteo Cyber Score in October 2025 ??
What was ODIDO's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on ODIDO's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ODIDO ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ODIDO's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?