In one of the most significant data breaches in Dutch history, telecom giant Odido and its subsidiary Ben were compromised by cybercriminals through a single phone call in February 2026. The attackers, identified as the ShinyHunters group, exploited social engineering tactics to infiltrate the company’s systems, affecting over six million customers.
How the Breach Unfolded
The breach was initiated when a man, speaking in Dutch but using specific IT jargon, contacted Odido’s customer service on February 5 and 6. Posing as an IT department colleague, he claimed a critical issue needed resolution. This led the employee to grant access to what appeared to be a legitimate system, which was actually a credential-stealing trap.
During this interaction, the attacker acquired sensitive information, including a username, password, and a multi-factor authentication token, which allowed them to bypass one of Odido’s security measures.
Impact on Customer Data
With the stolen credentials, the attackers accessed Odido’s Salesforce-based customer relationship management system. By February 7 and 8, they had extracted approximately 90 GB of data, comprised of 15 million records, without triggering security alerts.
Odido confirmed the breach, stating that 6.39 million customers, both current and former, were impacted. The stolen information included names, addresses, phone numbers, email addresses, birth dates, customer numbers, and bank details. However, Odido insists that passwords and billing data were not compromised, despite ShinyHunters’ claims to the contrary.
Response and Ongoing Investigation
Following the breach, ShinyHunters demanded a ransom of one million euros, which Odido refused to pay. Consequently, the cybercriminals released the data in stages, starting February 26 and completing by March 1. This led to a surge in phishing attempts, highlighting the immediate risks of leaked personal data.
The Dutch police have been investigating the incident since its disclosure. In July 2026, they announced potential involvement of Dutch nationals, focusing on the individual who made the fraudulent call. After no voluntary confessions, the police aired the caller’s voice on a true-crime program to encourage public identification.
Security experts have identified three critical failures that enabled the breach: lack of callback verification, excessive access privileges, and insufficient monitoring of data transfers. The ShinyHunters group has previously used similar tactics against other organizations globally, often bypassing security measures without technical hacks.
The investigation continues, with authorities urging anyone with information to contact them through various channels. This incident underscores the importance of robust security protocols and highlights the ongoing threat of social engineering attacks in the digital age.
