# Dutch Police Identify Homegrown Hackers Behind 6.2 Million-Customer Odido Breach
The Dutch National Police has uncovered "strong indications" that domestic cybercriminals were responsible for a massive February 2026 breach at Odido, one of the Netherlands' largest telecommunications providers. The investigation reveals a sophisticated social engineering attack that combined vishing (voice phishing) and credential theft, exposing personal data for 6.2 million customers and cementing the ShinyHunters extortion gang's position as one of the world's most prolific corporate raiders.
## The Incident: Timeline and Scope
On February 7, 2026, attackers breached Odido's customer contact database, gaining unauthorized access to personal information spanning millions of Dutch residents. The company publicly disclosed the incident on February 12, triggering a firestorm of concern across the Netherlands' telecom sector. Days later, the ShinyHunters gang claimed responsibility, posting an 88GB archive containing over 15 million records to their dark web leak site—significantly more than the company initially disclosed.
Odido provides mobile, broadband, and television services to millions of Dutch households and businesses. The breach represents one of the largest telecommunications data compromises in European history.
### Exposed Data
The attackers accessed highly sensitive personal information, including:
### What Was *Not* Compromised
Odido stressed that the following remained secure:
## The Attack Method: Vishing and Impersonation
The Dutch National Police's investigation revealed a methodical social engineering approach. According to police statements, a Dutch-speaking man called Odido customer service and impersonated an Odido IT employee. Through this deceptive phone conversation, the attacker manipulated the company into opening phishing links or compromising internal credentials.
"This type of investigation is often complex and takes time, but cybercriminals are also vulnerable and leave traces. Traces have been secured at several times during the investigation," said Stan Duijf, head of operations at the National Investigation and Interventions Unit.
The vishing attack demonstrates the continued effectiveness of human-targeted social engineering, even against large organizations with dedicated security teams. By mimicking internal staff and creating a false sense of urgency or legitimacy, attackers can bypass technical controls and gain initial access to corporate systems.
## ShinyHunters: A Profile in Prolific Cybercrime
The ShinyHunters extortion gang has emerged as one of the world's most active and damaging threat groups. Originally known for targeting SaaS platforms, the group has evolved into a sophisticated operation that combines social engineering, credential theft, and data extortion.
### Known Tactics
ShinyHunters specializes in targeting enterprise single sign-on (SSO) systems—particularly those from Okta, Microsoft, and Google. The group's modus operandi involves:
1. Vishing campaigns impersonating IT support staff
2. Phishing links designed to capture credentials and MFA codes
3. SSO compromise granting access to dozens of connected cloud applications
4. Mass data theft from SaaS platforms including Microsoft 365, Google Workspace, Salesforce, SAP, Slack, Zendesk, Dropbox, Adobe, Atlassian, and others
5. Extortion and data sales through dark web leak sites
### Notable Previous Targets
| Organization | Industry | Impact |
|---|---|---|
| Google | Technology | Significant credential theft and data access |
| Cisco | Networking/Security | Enterprise network compromise |
| Match Group | Online Dating | Millions of user profiles exposed |
| Rockstar Games | Entertainment | Source code and internal data |
| European Commission | Government | Sensitive EU institutional data |
| McGraw-Hill Education | EdTech | Student and educator records |
| PornHub | Adult Entertainment | User account information |
| Snowflake Customers | Cloud Data | Breaches affecting 165+ organizations |
| University of Nottingham | Higher Education | Research and personal data |
The group has also been linked to over 100 organizational breaches following exploitation of an Oracle PeopleSoft zero-day vulnerability, demonstrating both broad targeting capability and technical sophistication.
## Implications for Telecommunications and Consumer Privacy
The Odido breach carries significant consequences across multiple stakeholder groups:
### For Dutch Consumers
### For Telecom Providers
### For Enterprise Security Teams
## Recommendations for Organizations
### For Telecommunications Providers
### For Enterprise Security Teams
### For Individuals Whose Data Was Exposed
---
## HackWire Analysis
The Odido breach represents a critical inflection point in how we understand modern cybercrime targeting. ShinyHunters didn't develop sophisticated zero-days or break encryption—they simply called a telecom company and lied convincingly enough to manipulate human operators into providing access. This is not a failure of Odido's technology; it's a failure of the social infrastructure that governs trust within organizations.
What's particularly noteworthy is the *domesticity* of this attack. Dutch police identified that Dutch-speaking attackers were involved in a breach of a Dutch company targeting Dutch citizens. This breaks the traditional narrative that cybercrime is a borderless activity conducted by anonymous actors in distant jurisdictions. The Odido case suggests that sophisticated organized crime is increasingly localized—actors operating within the same country, using native language fluency, and possessing detailed operational intelligence about target organizations.
The 6.2 million customer figure is also a massive scale indicator. Odido's breach is roughly equivalent to compromising one-third of the Netherlands' entire population. For comparison, it dwarfs most corporate breaches, rivaling only the largest government data exposures. Yet the sheer volume of exposed IBANs—Dutch bank account numbers—represents a particular risk vector that security reporting has largely undersold. Unlike compromised email addresses or phone numbers, IBANs enable direct financial targeting and can facilitate invoicing fraud, account takeover, and unauthorized wire transfers.
The critical insight: organizations cannot security-engineer their way out of a social engineering attack when the attacker has cultural and linguistic fluency. Technical controls, SIEM monitoring, and MFA are all important—but they fail when someone who sounds like an internal employee asks for credentials in Dutch, under time pressure, and with enough operational details to seem legitimate. The defense here is organizational discipline around verification procedures, not just cybersecurity tooling.
— HackWire Editorial
---
## Related Coverage