Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23
On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).
On 7–8 February 2026, Dutch telco Odido suffered a cyberattack targeting a customer relationship system. Confirmed outcome: data of ~6.2 million people exposed. Here is the SOC/SIEM stack that enables ILR alerting within 24 hours and averts the worst.
What happened
On 7–8 February 2026, Odido (the leading mobile operator in the Netherlands) announced unauthorized access to a customer relationship management system, with personal data exfiltration affecting approximately 6.2 million people. Public information indicates the intrusion targeted a “customer contact” environment, involved social engineering, and created identity-fraud risks. The scale was corroborated by several outlets: The Record (11/02/2026) reports data theft of 6.2 million customers; The Register (13/02/2026) specifies the customer contact system was hit and notified to the Dutch authority; SecurityWeek (Feb 2026) confirms the 7–8 Feb timeline and the 6M+ order of magnitude. Odido’s CEO later published remediation commitments on 24/05/2026 (Odido newsroom).
Why should Luxembourg executives care? Because the same NIS2 obligation now applies in Luxembourg and across the EU: detect fast, contain, and notify within 24h/72h/1 month with substantiated facts. Without continuous detection (logs, correlations, IOCs, UEBA) and tooled response procedures, notification becomes late, incomplete, or inaccurate — inviting enhanced supervision.
The applicable legal framework
Article 23 of the Directive (EU) 2022/2555 (NIS2) mandates:
- an early warning “without undue delay and at the latest within 24 hours” after becoming aware of a significant incident;
- an incident notification “at the latest within 72 hours,” with an initial assessment (severity, impact, IOCs);
- a final report “at the latest one month” after the 72h notice, with root-cause analysis, actions taken, and lessons learned.
References: EUR‑Lex — NIS2, Art. 23 and the Commission’s application guidance (guidelines Art. 4(1)-(2)).
In Luxembourg, the ILR publicly details this sequencing and content expectations: early alert in 24h, notification in 72h, final report within a month, via the national portal (ILR — Incident notification | French version). The government also launched a centralized portal (SERIMA) to streamline NIS1/NIS2, CER, and GDPR notifications to competent authorities (government.lu release, 02/05/2025).
The technical solution to deploy
A 24/7 managed SOC backed by a modern SIEM is the proportionate way to:
- Collect and correlate critical logs (IAM/SSO, M365, Salesforce/CRM, VPN, EDR, proxies, firewalls, CASB);
- Detect within minutes exfiltration signals (abnormal volume, API access, bypassed DLP), internal lateral movement, and suspicious token/session use (UEBA);
- Quickly assemble NIS2 Art. 23 essentials: timestamps, scope, IOCs, techniques used, initial impacts, and containment actions;
- Automate response (SOAR): isolate account/device, revoke OAuth tokens, block IPs/domains/ASNs, rotate/purge secrets, and notify internal stakeholders (CIO, DPO, executives).
Supporting standards: ISO/IEC 27001:2022 Annex A (logging & monitoring, incident management), NIST CSF 2.0 (DE.CM Detection/monitoring; RS.CO Response communications), and CIS Controls v8 (C8 Audit Log Management, C17 Incident Response Management).
For an “Odido‑like” risk: the SIEM should ingest CRM/SaaS logs (e.g., Salesforce Event Monitoring), IdP (SSO/MFA), access gateways (ZTNA/VPN), and EDR/XDR. Deploy dedicated use cases: cross‑tenant API connections with abnormal volume, bulk extraction of sensitive objects, CRM privilege escalation, authentications from unexpected ASNs despite MFA, and token replay correlated with OAuth consent logs. The SOAR handles enrichment (WHOIS, GeoIP, reputation), escalation, quarantine, and produces a structured 24h/72h draft report ready for SERIMA/ILR.
How Luxgap delivers this
- Our 24/7 managed SOC: we operate the SIEM (on‑prem/cloud), integrate key sources (IAM, business SaaS, EDR/XDR, network), provide an exfiltration/SaaS‑focused use‑case library and NIS2 runbooks. We handle on‑call, L1/L2/L3 triage, and management/DPO escalation.
- Our ISO 27001 governance: policies and evidence (log registry, response plan, RACI, ILR notification drills), mapping of systems under NIS2, and CNPD alignment for GDPR/NIS2 interplay.
- Our external DPO and CISO consultants: legal/operational coordination during incidents: qualifying a “significant incident,” 24h trigger, personal‑data triage (GDPR Art. 33/34), and stakeholder communications. For data protection, see our DPO mandate.
Our approach is tooled: native connectors (incl. Salesforce, Microsoft 365, Okta/Entra, Google Workspace), ILR report templates (24h/72h/1 month) ready to fill, and “proof of detection” dashboards for audits.
Concrete case in Luxembourg or the EU
Real (anonymized) example: a digital service operator active in Luxembourg and categorized as a NIS2 “important entity” observed weak signals on a European CRM SaaS (night‑time export spikes). In 6 weeks we: connected CRM/IdP/EDR logs to the SIEM, deployed exfiltration use cases, formalized escalation playbooks and the ILR notification pack. Two months later, an OAuth token reuse attempt was detected and blocked automatically (SOAR: token revocation, key reset, IP block). The organization issued a substantiated early alert within 24 hours and, most importantly, contained the incident with no confirmed data loss.
First practical steps
- Plug critical SaaS into the SIEM: enable Salesforce Event Monitoring (or equivalent), connect the IdP (MFA/SSO), EDR/XDR, and network. Without logs, there’s no detection or evidence.
- Deploy 10 exfiltration use cases targeting bulk exports, cross‑boundary API access, CRM privilege escalations, and auth anomalies (impossible travel, MFA bypass).
- Pre‑populate the 24h/72h/1‑month ILR templates: teams, contacts, critical systems, SERIMA channels, and available IOCs/logs. Run a 1‑hour tabletop drill.
- Automate 5 SOAR actions: temporary account disable, session/token revocation, IP/domain block, enable stricter DLP rules, create an investigation ticket.
- Align GDPR/NIS2: build the DPO–SOC bridge: when to trigger GDPR Art. 33/34, what to notify (data categories, measures), and how to sync with ILR (24h/72h/1 month).
Official sources
- Odido incident: The Record (11/02/2026); The Register (13/02/2026); SecurityWeek (Feb 2026); Odido — CEO update (24/05/2026).
- NIS2 Art. 23 obligation (24h/72h/1 month): EUR‑Lex — Directive 2022/2555; Commission communication (guidance).
- Luxembourg (ILR): ILR — Incident notification (EN) | (FR); SERIMA portal: government.lu release (02/05/2025).
- Good‑practice references: ENISA — Threats & Incidents.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →