Dutch telecom operator Odido lost the personal data of roughly 6.2 to 6.39 million current and former customers after a single Dutch-speaking caller talked a helpdesk employee into logging in to a cloned Odido portal on 5 and 6 February 2026. The credentials and the multi-factor code that followed gave the extortion crew ShinyHunters access to Odido's Salesforce-based CRM, and the data of Odido and its budget brand Ben went out the door within days. Odido refused to pay; the full dataset was published on the dark web on 1 March. Seven months later, Dutch police went public with the suspect's voice on the television programme Opsporing Verzocht, and ShinyHunters responded by announcing it had hired the man a criminal defence lawyer and threatening another large-scale theft in the Netherlands.
One sourcing note up front: every source available for this brief is second-tier or aggregator press, including one item (hackersradar.com) that carries a recycled Ticketmaster headline over Odido reporting and should be treated with corresponding caution. Odido's own breach notification and any Autoriteit Persoonsgegevens filing were not available; figures below are attributed accordingly.
What Happened
The reconstruction broadcast by Opsporing Verzocht and reported by NOS describes a caller who had already phoned Odido several times before he succeeded. Other employees had flagged those earlier calls to the company's security department. On the successful attempt, the caller convinced a customer service employee that he was a colleague from IT with an urgent internal problem, walked her to a rebuilt Odido login page, and captured her username and password, then the additional verification code. NOS reports the police describe the tradecraft as "heel gewiekst" (very cunning) and note the caller's conspicuous use of English-language IT jargon, which investigators read as a sign he has worked in, or is closely familiar with, that kind of environment.
Hackify's timeline puts discovery on 7 and 8 February and customer notification on 12 February. NOS reports that two days after the hack succeeded, ShinyHunters emailed Odido claiming it had stolen millions of customer records. Accounts differ slightly on the extortion sequence: Cybernews dates the public claim of responsibility to 24 February with the leak following "a few days later," while Hackify places the ransom refusal and first data release on 26 February, with the complete dataset online on 1 March. These are compatible readings of the same fortnight rather than a substantive conflict, but no primary timeline confirms either.
Attribution is not seriously contested. ShinyHunters claimed the attack, and after the 7 September broadcast the group told Dutch outlet BNR that the man in the recording is one of its members: "Our team member has our full support, emotionally, mentally, and financially," adding that a criminal defence lawyer had been arranged. The same statement, reported by NLTimes and Cybernews, called Dutch police "a big joke" and warned they would need "all the luck in the world" to catch him "before we carry out another large-scale data theft in the Netherlands."
What Was Taken
Reported record counts vary and should be stated as a range. Cybernews, NLTimes, News Brainport and Hackify all put the figure at 6.2 million current and former customers. The hackersradar.com and Daily Tech Feed write-ups cite approximately 6.39 million affected individuals, with Daily Tech Feed noting that earlier figures floated between 6.1 and 6.2 million before the count settled higher. DarkDotWeb says only "more than six million." No primary Odido statement is available to arbitrate, so treat 6.2M as the widely repeated floor and 6.39M as the higher figure reported by the aggregator tier.
The data types are consistent across sources. Cybernews and Hackify, the latter citing NOS, list full name, postal address and place of residence, telephone number, customer number, email address, bank account number (IBAN), date of birth, and the numbers and expiry dates of identity documents such as passports and driving licences. Hackify notes the compromised system also held data on customers of Ben, part of Odido, and on the acquired Tele2 brand, but not on Simpel customers.
Two claims rest on a single lower-confidence source and are flagged as such. The Daily Tech Feed reports that roughly 90 gigabytes covering about 15 million database rows were pulled out on 7 and 8 February through legitimate Salesforce APIs, so the traffic resembled normal operations, and that ShinyHunters separately claimed a haul of up to 21 million records, a figure the outlet suggests inflates the total with internal metadata and duplicates. Neither the volume figure nor the 21 million claim is corroborated elsewhere in this source set.
Why It Matters
This is a full identity kit, not a marketing list. Name plus address plus date of birth plus IBAN plus passport or driving licence number is enough for account takeover at other providers, SIM swap attempts, direct debit fraud and synthetic identity creation, and none of it can be rotated the way a password can. For a population of six million in a country of roughly eighteen million, that is a meaningful fraction of Dutch adults.
The downstream abuse is measurable. Dutch security firm Hackify ran a natural experiment: two staff members using unique per-service email aliases were in the dataset, with one alias given only to Odido and one only to Tele2. In the 150 days after the full dump went online on 1 March, those two aliases received 61 phishing emails, 32 on the Odido address and 29 on the Tele2 address. Because the aliases had no other exposure, every one of those messages is traceable to this breach. That is the concrete cost of a dump that stays permanently available to anyone who knows where to look.
There is also a governance data point worth recording. Odido CEO Søren Abildgaard, speaking at the NLconnect industry conference on 9 September and reported by News Brainport, defended the refusal to pay as ethically difficult but correct, arguing that payment buys a false sense of security since there is no way to know a stolen database was ever deleted, and that paying to protect short-term reputation funds organised crime. Dutch police guidance points the same way. Abildgaard also conceded that Odido communicated poorly in the immediate aftermath, holding back updates while it tried to verify facts, which drew heavy public criticism. The leak happened either way; the payment refusal did not prevent publication, and organisations weighing the same decision should plan on that outcome.
The Attack Technique
No exploit, no malware, no vulnerability. The chain was: pretext call to the helpdesk from someone posing as internal IT, a manufactured urgent problem, a credential-harvesting page built to look like the real Odido login, capture of username and password, and then capture of the MFA code the victim was prompted to supply. That last step is the load-bearing one. Push-based or one-time-code MFA is phishable in real time by an attacker relaying the challenge, which is precisely what appears to have happened here. Once inside, the actor moved to the Salesforce CRM and, per the Daily Tech Feed account, exported through sanctioned API paths rather than anything that looked anomalous.
Two details raise the operational bar for defenders. First, the caller was persistent: NOS reports he had phoned multiple times before succeeding, and other employees had escalated those calls to security. The signal existed inside the organisation and did not stop the attack. Second, the police voice expert concluded the recording is a genuine human voice, not AI-generated, and the police profile describes a Dutch-speaking man with IT knowledge who uses specific English technical terminology. This was a native-language insider-flavoured pretext, not a machine-translated script, which is materially harder for a helpdesk agent to catch.
The investigation continues. Police asked the caller to come forward in July; he did not, which is why the recording was aired. News Brainport reports police confirmed on 8 September that the broadcast produced twenty tips containing highly relevant information. No arrests have been made.
What Organizations Should Do
- Move helpdesk and admin accounts to phishing-resistant MFA. FIDO2 security keys or passkeys bound to the origin cannot be relayed to a cloned login page. Any scheme where a human reads or approves a code, including push approval and TOTP, is defeated by exactly this attack.
- Build a hard identity-verification procedure for internal IT support calls, and make it unskippable. Callback to a number from the directory, verification through a separate channel, or ticket-reference confirmation. State explicitly that urgency is never a reason to bypass it, since urgency is the pretext.
- Treat repeat suspicious calls as an active incident, not a log entry. Odido employees did report earlier calls to security. Ensure helpdesk pretext reports trigger a same-shift broadcast to every agent and a temporary heightened-verification posture, not a queued ticket.
- Instrument SaaS CRM exports as first-class telemetry. Volume, row-count and API-rate thresholds per user account in Salesforce or equivalent, with alerting on any single session pulling beyond a normal working baseline. This breach reportedly moved through authorised APIs, so authentication logs alone would not have caught it.
- Minimise and segregate the crown-jewel fields. Identity document numbers, dates of birth and IBANs rarely need to sit in a CRM record that thousands of service agents can read and export. Tokenise them, restrict them to a separate system with its own authorisation, and cap what a single service session can retrieve.
- Rehearse the extortion and disclosure decision before it happens. Odido's CEO now says the refusal was right and the communications were wrong. Pre-agree who decides on payment, and pre-draft a disclosure cadence that publishes what is known and what is not rather than waiting for full certainty.
- For affected individuals and for organisations serving them: expect long-tail phishing referencing genuine account details. Watch for direct debit changes, treat unsolicited calls claiming to be from the provider as hostile, and where identity document numbers were exposed, consider registering that fact with the relevant fraud-prevention body.
Sources: ShinyHunters Breaches Ticketmaster, Exposing 560 Million Customer R... | ShinyHunters lawyer up after police release audio clip of suspect i... | Odido hackers mock police, threaten another Netherlands hack Cyber... | Odido CEO defends refusal to pay ransom following massive data leak... | Odido data breach: 150 days and 61 phishing emails later Hackify | ShinyHunters’ Social Engineering Exploit Leaks 6M Odido Records – T... | Odido-hacker te horen in Opsporing Verzocht: 'Hij ging heel gewieks... | ShinyHunters Offers Lawyer After Odido Hack Voice Released – DarkDo...