Wholesale Banking
Medium_Office 365-Man working late and sitting in the dark, looking and pointing at his computer screen

What businesses can learn from the Odido cyber incident

20 August 2026

Reading time: 3 min

Cyberattacks rarely begin with sophisticated technology. More often, they start with a simple human interaction.

An employee receives what appears to be a legitimate email. The message looks authentic and creates a sense of urgency. A link is clicked, login details are entered, and nothing immediately seems wrong.

Shortly afterwards, the employee receives a call from someone claiming to be from IT support. The caller reports suspicious activity and urges immediate action. During the conversation, a multi-factor authentication (MFA) request appears on the employee's phone. Reassured by the caller, the employee approves the request.

Within moments, cybercriminals gain authorised access to business systems using legitimate credentials. No malware is deployed and no technical vulnerability is exploited. Instead, access is granted through a simple but powerful tactic: convincing a trusted employee to provide it.

Incidents such as Opens in a new tabthe attack affecting Dutch telecommunications provider Odido demonstrate how effective social engineering remains.

According to public reports, customer data was accessed after attackers obtained legitimate credentials. The incident highlights a growing trend in cybercrime: targeting  users rather than technical vulnerabilities.

Why does transparency matter after a cyber incident?

It is also worth recognising Odido for Opens in a new tabopenly sharing information about the incident. While many organisations are understandably reluctant to discuss cyber incidents publicly, transparency helps the wider business community learn from real-world experiences. By sharing lessons learned, organisations enable others to strengthen their defences and better prepare for similar threats.

Why do social engineering attacks still work?

Most organisations invest heavily in cybersecurity technology. Firewalls, endpoint protection, monitoring systems and advanced threat detection all play a crucial role in reducing risk.

Yet attackers increasingly target people rather than technology. Social engineering attacks are designed to exploit trust, routine and a willingness to help. By impersonating colleagues, IT staff, suppliers or trusted organisations, criminals create situations where even security-conscious employees may make a mistake.

The challenge is that these attacks often appear legitimate. Business operations continue as normal and there may be no immediate signs of compromise .

According to Opens in a new tabENISA's Threat Landscape reporting, social engineering remains a significant cybersecurity threat across the European Union.

Why wasn't multi-factor authentication enough on its own?

Multi-factor authentication (MFA) is one of the most effective safeguards against account compromise. According to Opens in a new tabMicrosoft's 2025 Digital Defense Report, MFA prevents more than 99% of automated account-compromise attacks, making it a critical layer of defence against credential theft and phishing campaigns.

However, attackers have adapted.

Rather than bypassing MFA, they increasingly use social engineering to persuade users to approve authentication requests themselves.

This highlights an important reality: MFA is not just a technical safeguard but also a human one. Employees should treat unexpected authentication requests as a warning sign and verify them before taking action.

Why is independent verification essential for preventing social-engineering attacks?

One of the key lessons from incidents such as the Odido attack is that trust alone is no longer sufficient in the digital world.

Opens in a new tabEuropean Union Agency for Cybersecurity (ENISA) advises organisations to confirm unexpected requests through trusted communication channels before sharing credentials, approving access or taking other sensitive actions.

In many cases, a brief pause to verify is all it takes to stop an attack.

Businesses can reduce the risk of social-engineering attacks by:

  1. Training employees to recognise phishing and impersonation attempts.
  2. Treating unexpected MFA requests as potential warning signs.
  3. Verifying sensitive requests through an independent communication channel.
  4. Combining technical controls with ongoing security awareness.
  5. Creating a culture where employees stop and verify before acting.

Learn more about banking safely.

Authors

Jules Vandalon

Fraud Management Product Expert

Jules Vandalon