The investigation is still ongoing. As soon as more information becomes available, we will update this page.
Last update on March 24, 2026, 15.20 pm
The latest updates
March 2, 2026, 19.30 pm
Please be aware of a phishing email sent in Ben's name that references the cyberattack. The message urges you to click a link and fill in a so-called mandatory “compensation request form". This is not an Ben email. Do not click any links, do not provide any information, and delete the email. Official Ben emails on this topic are sent exclusively from info@mail.ben.nl and contactformulier@ben.nl. Always check the sender's email adress, not just the name you see.
February 26, 2026, 11.45 am
Our focus has always been, and continues to be, our customers. Following the guidance from leading cybersecurity experts and relevant government authorities, such as the police, Odido came to the decision not to engage in negotiations with these criminals or submit to their attempts at blackmail. We continue to put all of our efforts toward supporting our customers and our employees to the best of our ability.
Extra protection for you – free of charge
We want to support you. We want to offer some additional data protection free of charge.
You can activate the F‑Secure digital security package free of charge for 24 months. It gives your phone, tablet and computer extra protection against viruses, phishing and other online threats. You activate the package using a voucher.
Why this page?
Ben has been affected by a cyberattack, in which customer data has been impacted. This involves personal data originating from a customer contact system used by Ben. We are still investigating whether and to what extent other systems have also been affected. Based on what we know at this time, no passwords, call records, or billing information are involved. The investigation is ongoing. As soon as more information becomes available, we will share further updates via this page.
We deeply regret this incident and are fully committed to limiting the impact of this incident and providing our customers with all necessary support. It is important to emphasize that our operational services have not been affected; customers can continue to call and use the internet.
Unauthorized access to the system was ended as quickly as possible. In addition, Ben has engaged external cybersecurity experts to support the implementation of additional security measures as part of the response to this incident.
Affected customers have received an email directly from the email address info@mail.ben.nl or an SMS from Ben. If we determine that your data was impacted, and you have not already heard from Ben, we will inform you directly. Ben has also reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).
On this page we share more information about this incident, a frequently asked questions section, and any important updates. You can also read here about steps you can take yourself, in addition to the measures Ben has already taken.
Be extra alert for suspicious and unusual activities. Unfortunately, cyberattacks like this are becoming increasingly common and no organization is immune. Not every data breach leads to actual misuse, but we cannot rule out the possibility that your data may be misused.
Below are concrete situations where we ask you to be extra alert:
- With your name, address, phone number, email address and bank account number, cybercriminals may try to contact you while pretending to be someone from Ben, your bank, or another organization. Therefore, always remain alert to these kinds of phone calls, text messages, app messages, or emails.
- Be careful when opening links in emails, text messages, and app messages. You can often recognize a suspicious email, text message, or app message by typos and unknown senders. Check the phone number, or what appears after the “@” sign in an email address.
- Do you receive an unexpected call from a number you don’t know? It may indeed be an employee of your bank or another company calling. You can verify this by asking the caller for their first and last name and asking for the company’s general phone number. If in doubt, say you would like to verify first whether the person is a real employee and hang up. Then check the company’s website to see whether the number is correct. Is the number correct? Then call the company yourself and ask for the employee who called you.
- Never give anyone your password or PIN code.
- Always be alert when receiving invoices. Cybercriminals may exploit the situation by sending fake invoices that appear to come from Ben or other parties. Therefore, always carefully check the origin and accuracy of received invoices before proceeding with payment. For example, you can always view an Ben invoice in your “Ik Ben” environment. If in doubt, always contact us.
The email we sent you is decisive for your personal situation. It states exactly what applies to you.
The information involved may include:
- Full name
- Address and city of residence
- Mobile number
- Customer number
- Email address
- Date of birth
- Identification details (passport or driver’s license number and validity)
What information is not involved?
The information involved does not include:
- 'Ik Ben' passwords
- Call details (who you called, when)
- Location data
- Billing data
Scans of identity documents
The investigation is ongoing. As soon as more information becomes available, we will share further updates via this page.
We always want to be transparent with our customers, and we want to inform you so you can be alert to any unusual activities. We also want to emphasize that your security is our highest priority. Because of this incident, no one can view your mobile location data or your private contacts.
Ben is working together with external cybersecurity experts as part of our response to this incident.
- Security strengthened – After the discovery of the attack, unauthorized access to our system was immediately shut down. Ben immediately took additional security measures.
- Regulation & transparency – We reported the data breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).
- Support – We want to help you. That’s why we have opened this special information page.
We would like to keep you informed via this web page about any important new information regarding this security incident. Our customers received a personal email or an SMS about this incident. Keep an eye on this information page in the coming period.
We understand you may have questions. Consult this page for the most up-to-date updates. Our customer service colleagues cannot provide any additional information at this time beyond what is shared here.
Again, we deeply regret this situation and are fully committed to providing you with all necessary support.
You are our customer, and your interests come first.
Søren Abildgaard
CEO Odido Netherlands (Ben is part of Odido Netherlands)
These FAQs may be supplemented. If you have new questions, first check out this information page to see if new information is available before contacting us.
About the incident
Negotiations
Leaked data
Bank account number
Identification details
Login details
Details of former customers
Compensation
Contact
We understand that you may still have questions. We ask you to check this page for updates. Our customer service team is currently not able to provide more information than what can be found on this page.
If you do have urgent questions, please contact us.