# Dutch Police Identify Homegrown Hackers Behind 6.2 Million-Customer Odido Breach


The Dutch National Police has uncovered "strong indications" that domestic cybercriminals were responsible for a massive February 2026 breach at Odido, one of the Netherlands' largest telecommunications providers. The investigation reveals a sophisticated social engineering attack that combined vishing (voice phishing) and credential theft, exposing personal data for 6.2 million customers and cementing the ShinyHunters extortion gang's position as one of the world's most prolific corporate raiders.


## The Incident: Timeline and Scope


On February 7, 2026, attackers breached Odido's customer contact database, gaining unauthorized access to personal information spanning millions of Dutch residents. The company publicly disclosed the incident on February 12, triggering a firestorm of concern across the Netherlands' telecom sector. Days later, the ShinyHunters gang claimed responsibility, posting an 88GB archive containing over 15 million records to their dark web leak site—significantly more than the company initially disclosed.


Odido provides mobile, broadband, and television services to millions of Dutch households and businesses. The breach represents one of the largest telecommunications data compromises in European history.


### Exposed Data

The attackers accessed highly sensitive personal information, including:

  • Full names
  • Residential addresses and city information
  • Mobile phone numbers
  • Customer account numbers
  • Email addresses
  • International Bank Account Numbers (IBANs)
  • Dates of birth
  • Government-issued identification details (passport or driver's license numbers and expiration dates)

  • ### What Was *Not* Compromised

    Odido stressed that the following remained secure:

  • Call detail records or call logs
  • Geolocation data
  • Billing information
  • Scanned identity documents
  • Mijn Odido account passwords or multi-factor authentication codes

  • ## The Attack Method: Vishing and Impersonation


    The Dutch National Police's investigation revealed a methodical social engineering approach. According to police statements, a Dutch-speaking man called Odido customer service and impersonated an Odido IT employee. Through this deceptive phone conversation, the attacker manipulated the company into opening phishing links or compromising internal credentials.


    "This type of investigation is often complex and takes time, but cybercriminals are also vulnerable and leave traces. Traces have been secured at several times during the investigation," said Stan Duijf, head of operations at the National Investigation and Interventions Unit.


    The vishing attack demonstrates the continued effectiveness of human-targeted social engineering, even against large organizations with dedicated security teams. By mimicking internal staff and creating a false sense of urgency or legitimacy, attackers can bypass technical controls and gain initial access to corporate systems.


    ## ShinyHunters: A Profile in Prolific Cybercrime


    The ShinyHunters extortion gang has emerged as one of the world's most active and damaging threat groups. Originally known for targeting SaaS platforms, the group has evolved into a sophisticated operation that combines social engineering, credential theft, and data extortion.


    ### Known Tactics

    ShinyHunters specializes in targeting enterprise single sign-on (SSO) systems—particularly those from Okta, Microsoft, and Google. The group's modus operandi involves:


    1. Vishing campaigns impersonating IT support staff

    2. Phishing links designed to capture credentials and MFA codes

    3. SSO compromise granting access to dozens of connected cloud applications

    4. Mass data theft from SaaS platforms including Microsoft 365, Google Workspace, Salesforce, SAP, Slack, Zendesk, Dropbox, Adobe, Atlassian, and others

    5. Extortion and data sales through dark web leak sites


    ### Notable Previous Targets


    | Organization | Industry | Impact |

    |---|---|---|

    | Google | Technology | Significant credential theft and data access |

    | Cisco | Networking/Security | Enterprise network compromise |

    | Match Group | Online Dating | Millions of user profiles exposed |

    | Rockstar Games | Entertainment | Source code and internal data |

    | European Commission | Government | Sensitive EU institutional data |

    | McGraw-Hill Education | EdTech | Student and educator records |

    | PornHub | Adult Entertainment | User account information |

    | Snowflake Customers | Cloud Data | Breaches affecting 165+ organizations |

    | University of Nottingham | Higher Education | Research and personal data |


    The group has also been linked to over 100 organizational breaches following exploitation of an Oracle PeopleSoft zero-day vulnerability, demonstrating both broad targeting capability and technical sophistication.


    ## Implications for Telecommunications and Consumer Privacy


    The Odido breach carries significant consequences across multiple stakeholder groups:


    ### For Dutch Consumers

  • 6.2 million individuals have had sensitive personal data stolen, including bank account numbers and identification details
  • Increased risk of identity theft, financial fraud, and targeted phishing
  • Potential for SIM swapping attacks using phone numbers and account information
  • Long-term privacy exposure given the permanence of leaked data

  • ### For Telecom Providers

  • Demonstrates that customer contact databases remain attractive targets despite widespread awareness
  • Highlights the effectiveness of vishing against administrative staff with system access
  • Creates liability exposure for data protection compliance (GDPR in Europe)
  • Erodes customer trust in data security commitments

  • ### For Enterprise Security Teams

  • Reinforces that SSO compromise represents an existential threat to organizational security
  • Shows that internal impersonation attacks remain highly effective despite awareness campaigns
  • Underscores the need for multi-layered verification procedures, not just security awareness training

  • ## Recommendations for Organizations


    ### For Telecommunications Providers

  • Implement voice verification protocols beyond caller ID for sensitive requests
  • Segregate administrative systems from customer-facing databases
  • Audit access logs for all customer contact system queries in the past 12 months
  • Deploy voice biometric authentication for internal employee verification
  • Enforce conditional access policies that flag access from unusual locations or IP addresses

  • ### For Enterprise Security Teams

  • Assume SSO compromise and segment applications behind additional verification layers
  • Monitor for MFA code exfiltration through SIEM rules that detect unusual MFA usage patterns
  • Conduct vishing simulations to test employee susceptibility to social engineering
  • Implement phone-based anomaly detection for administrative support lines
  • Establish zero-trust architecture that requires continuous re-authentication

  • ### For Individuals Whose Data Was Exposed

  • Monitor financial accounts closely for unauthorized activity
  • Consider a credit freeze or fraud alert with Dutch credit bureaus
  • Watch for phishing attempts using exposed personal data for targeted attacks
  • Avoid responding to unsolicited calls claiming to be from Odido or other service providers

  • ---


    ## HackWire Analysis


    The Odido breach represents a critical inflection point in how we understand modern cybercrime targeting. ShinyHunters didn't develop sophisticated zero-days or break encryption—they simply called a telecom company and lied convincingly enough to manipulate human operators into providing access. This is not a failure of Odido's technology; it's a failure of the social infrastructure that governs trust within organizations.


    What's particularly noteworthy is the *domesticity* of this attack. Dutch police identified that Dutch-speaking attackers were involved in a breach of a Dutch company targeting Dutch citizens. This breaks the traditional narrative that cybercrime is a borderless activity conducted by anonymous actors in distant jurisdictions. The Odido case suggests that sophisticated organized crime is increasingly localized—actors operating within the same country, using native language fluency, and possessing detailed operational intelligence about target organizations.


    The 6.2 million customer figure is also a massive scale indicator. Odido's breach is roughly equivalent to compromising one-third of the Netherlands' entire population. For comparison, it dwarfs most corporate breaches, rivaling only the largest government data exposures. Yet the sheer volume of exposed IBANs—Dutch bank account numbers—represents a particular risk vector that security reporting has largely undersold. Unlike compromised email addresses or phone numbers, IBANs enable direct financial targeting and can facilitate invoicing fraud, account takeover, and unauthorized wire transfers.


    The critical insight: organizations cannot security-engineer their way out of a social engineering attack when the attacker has cultural and linguistic fluency. Technical controls, SIEM monitoring, and MFA are all important—but they fail when someone who sounds like an internal employee asks for credentials in Dutch, under time pressure, and with enough operational details to seem legitimate. The defense here is organizational discipline around verification procedures, not just cybersecurity tooling.


    HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Social Engineering](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)