Millions for Lawyers, Nothing for Security: The Odido Data Breach Court Case
I am the first plaintiff to take the Odido data breach case to court. On 22 June, in The Hague, a hearing took place against Odido…
Millions for Lawyers, Nothing for Security: The Odido Data Breach Court Case
I am the first plaintiff to take the Odido data breach case to court. On 22 June, in The Hague, a hearing took place against Odido regarding a massive data leak (victims — 6.2 million users whose IDs, addresses, and bank account details were publicly revealed). For four months, I requested a compensation and remediation plan from the company. Odido rejected every request and offered no pre-trial settlement. Instead, they brought in the world’s most expensive lawyers from Freshfields. This demonstrates a management culture defined by incompetence and chaos. Spending millions of dollars to silence victims, rather than addressing the root causes of a data breach, is the Odido style.

My First Taste of Odido’s Chaos
In November 2024, I purchased a smartphone and a mobile contract from Odido. The chaos within the organization was immediately apparent. It took until March 2025 for my service to be activated and for me to receive my first bill. To achieve even that, I had to call the company ten times (with zero results) and visit their physical offices three times. It felt like they had gifted me a smartphone and then simply forgotten I existed.
Even after the contract finally started, the billing was erratic; their system would frequently skip months or prevent payment via the app. Nevertheless, I continued using their services — being “enslaved” by a two-year contract leaves little choice. At the time, the company appeared somewhat flexible; I managed to establish contact not just with customer support leadership, but with the CEO himself. I shared the challenges I faced, including issues with setting up wired internet, and even offered recommendations to improve their services. Naturally, none of my suggestions were implemented, and the chaos continued to grow.
Odido Does Not Control Its Infrastructure
The situation regarding my second contract — for wired internet — was even more telling. In two months, despite sending three different technical teams, Odido failed to provide a connection. They were unable to answer a simple question: “Is this house, or this specific block, actually connected to your network?” They couldn’t even tell me where the switches were located. This was a clear indicator of total technological disorder and a major red flag regarding the company’s technical side. Seeing the lack of competence, I decided to switch to wireless internet (K&K), as it was evident that Odido’s representatives neither understood nor controlled their own infrastructure.
Two Contracts, Two Different Worlds
By the end of 2025, I held two contracts with Odido: a smartphone plan and the K&K wireless internet. The payment history was a tale of two realities. I was paying for one contract consistently, while the other was mired in chaos. The system would frequently fail, or I would see bizarre, unexplained charges. It became clear that the chaos was entirely on Odido’s side. With no time to chase them for payments, I eventually stopped trying in December 2025.



One user — two different discipline? Or Odido’s billing system technical failure? Technical failure and let’s see the movies…
[embed]
[embed]
The Final Straw - The Data Breach
In February 2026, one of the largest data breaches in Dutch history occurred. The chaos at Odido led to the theft of data from 6.2 million subscribers. It’s hard to even call it a cyberattack; the key factor was not sophisticated hacking, but “vishing” (voice phishing). A representative was manipulated over the phone, and she handed over access to internal systems.
But that is not the only problem. While human error is inevitable, any telecommunications company’s information security system should provide multi-layered protection, including “fool-proofing.” Odido had all of this on paper, and likely in a thousand corporate reports. This is a systemic issue across EU corporations: cybersecurity has become a matter of useless paperwork and meetings rather than actual defense.
What Failed at Odido (shortly and technical)?
- Complete failure of cybersecurity. No protection against unauthorized data access.
- Centralized data storage. Possibility of a full database export.
- SIEM/SOC system failure. No real-time threat detection.
- Firewall and WAF failure. No filtering of suspicious activity.
- Anti-fraud system failure. No alerts on anomalous actions.
- Lack of segmentation. Data was not partitioned.
- Combined storage. Data was stored without de-identification.
In short, Odido is a telecom company functioning with its cybersecurity systems effectively turned off.
How it Should Be vs. How Odido Handled It

Post-Breach: No Improvement
Four months have passed, and it appears the company has done nothing to mitigate risks. A serious cybersecurity audit would immediately highlight the need to reduce the “Attack Surface.” According to public services like dnsdumpster, the company still has over 100 different internal services accessible from the outside, some with outdated software versions and known vulnerabilities. As of 26 June 2026, Odido remains an easy target for hackers.




The Legal Struggle
After waiting for a notification from NordLayer confirming my data had been leaked, I filed a request for compensation. I was met with total disregard. Consequently, I stopped paying for one of my contracts until the company could provide a risk mitigation plan and a secure payment format.
Because Odido is better at debt collection than cybersecurity, they reacted repressively. Four weeks after my request for compensation, they reported me to credit and fraud bureaus (BKR and Preventel) without notice. I had anticipated this, as I had planned to take this to court. The blacklisting gave me grounds for a kort geding (summary proceedings), especially since neither Odido nor the BKR marked the debt as “disputed” under GDPR requirements.
The Courtroom Circus
The lawsuit was directed at two defendants: Odido and the BKR. They were shocked when they received notice of the hearing and realized I was serious. Frightened, they both retained top-tier legal counsel — BKR hired Kennedy Van Der Laan, and Odido hired the “Magic Circle” firm Freshfields, typically known for representing the British Royal Family.

The lawyers didn’t help much. During the trial, Odido’s defense was contradictory. Despite their claims that all processes are “fully automated,” the correspondence provided by the BKR showed that over ten people were manually trying to sort out Odido’s billing mess. They even attempted to “fix” the data and close the case retroactively during the court session. Both companies essentially ignored the core requirement of data accuracy under GDPR/AVG.
In an ironic twist, Freshfields actually helped me by confirming in court that my previous attempts to contact the Odido CEO and other staff had indeed occurred. They argued that my suggestions were dismissed as a “commercial pattern.” If they hadn’t mentioned it, I might have seemed like a disgruntled individual, but thanks to Freshfields, it is now on the record that I reached out to C-level management to prevent this disaster.
The circus continues, but the truth is now documented. Odido is a company that prefers to pay the world’s most expensive lawyers to cover up its own incompetence rather than spend that money on securing the data of its 6.2 million customers.
메타데이터
- post_id
- 35c23b01cd71
- slug
- millions-for-lawyers-nothing-for-security-the-odido-data-breach-court-case-35c23b01cd71
- url
- https://medium.com/@0trust0day/millions-for-lawyers-nothing-for-security-the-odido-data-breach-court-case-35c23b01cd71
- canonical_url
- https://medium.com/@0trust0day/millions-for-lawyers-nothing-for-security-the-odido-data-breach-court-case-35c23b01cd71
- author_url
- https://medium.com/@0trust0day
- status
- ok
- fetched_at
- 2026-06-27 07:40:21