Blog

Article

Have Companies Gotten Their Cybersecurity in Order Since the Odido Data Breach?

5 minutes
Have Companies Gotten Their Cybersecurity in Order Since the Odido Data Breach?

I recently read an article on NU.nl reporting that email addresses stolen in the Odido data breach are still being actively abused months later. By now, we have learned a great deal from this breach and the way it unfolded. But it did make me wonder: have companies actually gotten their cybersecurity in order since the Odido incident?

The Aftershock of Cybercrime

The Odido data breach was not an incident that ended when the database was stolen. Research by ethical hacker Rick Verdoes (Hackify), published by NU.nl, shows that the stolen email addresses are still being actively exploited months later. Between February and July, two monitored mailboxes received 61 phishing emails originating from approximately 30 different phishing campaigns.

Most of these campaigns were relatively simple. Criminals primarily used the leaked email addresses to send large-scale phishing emails impersonating well-known organizations such as banks, delivery services, and government agencies. Only one campaign specifically abused the Odido brand by attempting to trick victims into installing malicious software.

According to Verdoes, criminals are likely using only the easily accessible email addresses from the stolen dataset. The full database contains far more personal information, but processing and correlating that data requires more effort and expertise. As a result, attackers are choosing the fastest route: mass phishing campaigns.

The Key Question

Have companies gotten their cybersecurity in order since the Odido data breach?

The short answer is: no, there is currently no evidence that they have. In fact, the available information suggests that organizations remain highly vulnerable.

There are several reasons for this.

1. The Abuse of Stolen Data Continues for Months

The NU.nl investigation shows that stolen data is not used once and then discarded. Instead, it continues to circulate among different criminal groups over an extended period of time. A data breach is therefore not a one-time event, but the beginning of a long-term security threat.

2. Regulators Are Still Investigating Whether Odido Was Adequately Protected

The fact that regulators are still conducting investigations indicates that it has not yet been determined whether the security measures in place met legal requirements.

The Dutch Digital Infrastructure Inspectorate (RDI), the Dutch Data Protection Authority (AP), and later the Authority for Consumers and Markets (ACM) are investigating, among other things:

  • Whether the security of the systems complied with legal requirements.
  • Whether telecom providers fulfilled their duty of care regarding customer data.
  • Whether personal data was retained longer than necessary.

3. The Attack Exploited Human Vulnerability

Odido has publicly stated that the attackers gained access through a sophisticated form of voice phishing (vishing). Employees were convinced to grant access after criminals impersonated internal IT staff.

What makes this particularly noteworthy is that this attack method was already well known within the cybersecurity community. The FBI issued a warning in 2025 about cybercriminals targeting help desks, IT departments, and employees through phone calls, text messages, and emails to obtain credentials or access codes. According to the FBI, these attacks increasingly target organizations that rely on cloud platforms and identity services, where manipulating people is often more effective than exploiting technical vulnerabilities.

Salesforce, the platform used by Odido and ultimately accessed by the attackers, also published a warning in January about identity compromise. The company described how attackers use social engineering techniques to persuade employees to grant access to corporate environments. Salesforce emphasized that traditional security controls alone are not sufficient when identities or accounts are compromised.

This makes the Odido incident particularly relevant to the broader cybersecurity discussion. It demonstrates that organizations must invest not only in technical security controls, but also in identity management, access control, verification procedures, and employee awareness. When both technology vendors and law enforcement agencies warn about a specific attack technique in advance, and that technique is still successfully executed, it signals that many organizations continue to struggle with managing well-known risks effectively.

4. Organizations Are Investing More, but the Results Remain Unclear

Following the attack, Odido announced additional security measures, including increased investment in organizational security, improved communication verification processes, and additional protections for customers.

These are important steps, but they do not automatically mean that security is now sufficient. That is precisely why regulatory investigations are still ongoing.

What Can We Learn From This?

The Odido incident demonstrates that cybersecurity is not a project that can simply be completed. Many organizations focus heavily on prevention, while the consequences of a data breach often continue for months or even years.

Some key lessons include:

  • Human error remains a major attack vector.
  • Stolen data continues to circulate long after a breach occurs.
  • Email addresses alone are often sufficient for effective phishing campaigns.
  • Organizations must prepare for the period after a breach, not just focus on preventing one.
  • Effective security requires a combination of technology, processes, monitoring, and continuous awareness.

Conclusion

Based on the available information, the answer to the question "Have companies gotten their cybersecurity in order since the Odido data breach?" is no.

Not because organizations are doing nothing—many are investing more heavily in security—but because reality continues to show that:

  • The stolen data is still being actively abused months later.
  • Regulators are still investigating whether security measures met legal standards.
  • Human factors remain one of the largest cybersecurity risks.
  • The impact of a data breach does not disappear once the attack itself has ended.

The Odido data breach serves as a reminder that cybersecurity is not a destination. It is an ongoing process that requires continuous improvement across technology, people, and organizational practices.

Applied AI, without the theatre

Want to see how this works in your organisation?

We help teams turn AI concepts into working workflows, usable tools, and measurable operational gains.

Start a 14-day AI sprint

Further reading

Continue reading

A few more articles worth reading after this one.