Full Report
Odido is getroffen door een cyberaanval, waarbij gegevens van een aantal klanten zijn geraakt.Odido is getroffen door een cyberaanval, waarbij gegevens van klanten zijn geraakt. Het gaat hierbij om persoonsgegevens die afkomstig zijn uit een door Odido gebruikt klantcontactsysteem. Er zijn geen wachtwoorden, belgegevens of factuurgegevens betrokken. De ongeautoriseerde toegang tot het systeem is zo snel mogelijk beëindigd. Daarnaast heeft Odido externe cybersecurity-experts ingeschakeld om te ondersteunen bij het nemen van aanvullende beveiligingsmaatregelen als onderdeel van de respons op dit incident.
Analysis Summary
# Incident Report: Odido Customer Contact System Breach
## Executive Summary
Odido, a major Dutch telecommunications provider, was targeted by a cyberattack that resulted in unauthorized access to a specific customer contact system. The breach compromised the personal information of a number of Odido and Ben brand customers, though core operational services remained functional. Odido terminated the unauthorized access, notified regulators, and is working with external experts to bolster security.
## Incident Details
- **Discovery Date:** Not explicitly disclosed
- **Incident Date:** October 2024 (approximate based on reporting)
- **Affected Organization:** Odido (formerly T-Mobile Netherlands) and Ben
- **Sector:** Telecommunications
- **Geography:** Netherlands
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed
- **Vector:** Unauthorized access to a customer contact system.
- **Details:** Attackers exploited an unspecified vulnerability or access point in a system used by Odido for customer support and contact management.
### Lateral Movement
- **Details:** The report indicates access was limited to the customer contact system; there is no evidence currently provided of movement into core network infrastructure or billing systems.
### Data Exfiltration/Impact
- **Details:** Customer personal data was accessed. The scope includes Odido and Ben customers, while Simpel customers were unaffected.
### Detection & Response
- **How it was discovered:** Not disclosed (likely internal monitoring).
- **Response actions taken:** Immediate termination of unauthorized system access, engagement of external cybersecurity experts, and notification of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
## Attack Methodology
- **Initial Access:** Unauthorized access to a customer contact system.
- **Persistence:** Terminated by the organization.
- **Collection:** Data gathering from support databases.
- **Exfiltration:** Personal Identifiable Information (PII) including ID numbers and IBANs.
- **Impact:** Data breach leading to potential phishing and social engineering risks for customers.
## Impact Assessment
- **Financial:** Not disclosed; potential for regulatory fines.
- **Data Breach:** Compromised data includes: Full name, address, phone number, customer number, email address, IBAN, date of birth, and identification document numbers (Passport/Driver's License).
- **Operational:** No disruption to mobile, internet, or TV services.
- **Reputational:** High; requires public disclosure and direct customer notification via email (info[@]mail.odido.nl) and SMS.
## Indicators of Compromise
- **Network indicators:** None disclosed in public documentation.
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unauthorized queries within the customer contact management system.
## Response Actions
- **Containment measures:** Terminated unauthorized access to the affected system "as quickly as possible."
- **Eradication steps:** Implementation of additional security measures assisted by external experts.
- **Recovery actions:** Direct communication with affected individuals and setting up a dedicated information portal.
## Lessons Learned
- **Key takeaways:** Use of third-party or internal contact systems can represent a significant "soft target" for PII even if core billing/network systems are hardened.
- **What could have been done better:** (Inferred) Strengthening access controls and monitoring specifically for support systems that aggregate diverse customer data.
## Recommendations
- **Multi-Factor Authentication (MFA):** Ensure robust MFA is enforced for all support staff accessing customer contact systems.
- **Data Minimization:** Evaluate if ID and IBAN data need to be stored within the same contact system used by general support staff.
- **Monitoring:** Implement anomaly detection to alert on bulk data exports or unusual query patterns from support accounts.
- **Customer Vigilance:** Customers are advised to be alert for "vishing" (voice phishing) and "spoofing" where attackers use the stolen IBAN and ID details to pose as bank or Odido officials.