UTServicesLISACyber safetyNewsBusiness contact details also made public in Odido hack

Business contact details also made public in Odido hack

In early February, telecom provider Odido was hacked. During the breach, customer data belonging to more than 6.2 million customers was stolen. After Odido announced that it did not intend to pay the hackers to prevent the data from being released, the stolen data was subsequently published online.

Business contact details

Odido informed its customers about the incident. It has since become clear that the scale of the data breach is larger than initially thought. In addition to private customer data and contact person details, information relating to business end users has also been stolen and made public.

This also applies to our organisation. The University of Twente has a contract with Odido for employee telephony services. The leaked data includes the names and business contact details of a number of UT employees, such as their work phone number and email address. Odido has started informing the affected employees.

Risk of misuse

Although the data concerns business contact details, misuse cannot be completely ruled out. Criminals could use this information for targeted phishing, spoofing or other forms of digital fraud.

What you can do to help prevent misuse

We therefore ask everyone to remain alert, both to potential misuse of their own data and that of colleagues. Please pay attention to, for example:

  • unexpected emails, text messages or phone calls asking you to log in, share information or make payments;
  • messages that appear to come from colleagues or external partners but contain unusual requests;
  • small deviations in email addresses or phone numbers that may indicate spoofing or phishing.

If you are unsure about a message or request you receive, always verify it through another channel (for example by calling the sender directly or sending a new message). Never share passwords or sensitive information via email or phone.

By staying alert and helping each other recognise suspicious messages, we can limit the risk of misuse as much as possible.

If in doubt, please contact our IT security team at cert@utwente.nl or +31 (0)53 489 1313.