SYS::ONLINE
Wasteland.
Briefs2241
Issues25
SinceFeb 2026
LIVE
▣ Breach ODIDO-SHINYHUNTERS 2026-08-25

Odido: ShinyHunters Drip-Feed Extortion Leak

"The extortion group ShinyHunters has published a further 1 million customer records stolen from Dutch telecom operator Odido, the second tranche in a threatened daily release schedule. According to the reporting in S1…"

The extortion group ShinyHunters has published a further 1 million customer records stolen from Dutch telecom operator Odido, the second tranche in a threatened daily release schedule. According to the reporting in S1, an initial 1 million lines appeared on Thursday and a second million surfaced early Friday morning, with the group demanding more than €1 million and promising to dump another million records every day until it is paid. Odido has put the size of the stolen dataset at 6.2 million current and former customers; the attackers claim data on more than 8 million people. Dutch police have separately confirmed "strong indications" that Dutch nationals were involved in the February 2026 intrusion behind the theft.

What Happened

Odido, formed from the 2023 rebranding of T-Mobile Netherlands and Tele2 under Apax Partners and Warburg Pincus, is one of the largest mobile operators in the Netherlands, serving roughly 8 million mobile subscribers and about 1 million fixed broadband customers under the Odido, Ben and Simpel brands (Security Affairs).

The accounts of the intrusion timeline differ in detail. Hackify dates the attack to 5 and 6 February 2026, with discovery on 7 and 8 February and customer notification on 12 February. Data Security Wiki also places the attack on 5 and 6 February and reports that Odido detected and revoked the attackers' access on both occasions. Geek Feed, citing Odido's 12 February disclosure, states that attackers accessed the customer contact system on 7 February and downloaded personal data. Security Affairs describes the break-in more loosely as occurring "in mid-February." The common thread across all of them is a compromise of a customer contact system in the first half of February 2026, followed by bulk exfiltration.

The sources also diverge on what came next. Hackify reports that Odido refused to pay, that a first portion of data appeared on 26 February, and that the full dataset was posted to the dark web on 1 March. S1, covering the current release, describes an active drip-feed of 1 million lines per day against a lapsed ransom deadline. These are not easily reconciled: one account has the whole corpus already public since March, the other has it being metered out for leverage. Readers should treat the exact publication state of the dataset as contested. What is not contested is that a substantial volume of Odido customer data is now in circulation.

Attribution is likewise uneven. Data Security Wiki reports that Odido itself named ShinyHunters as the actor behind the social engineering campaign, while Geek Feed states the company had not attributed the incident and that ShinyHunters claimed responsibility unilaterally. ITdaily describes ShinyHunters as a "Russian group," a characterisation no other source here supports and one that sits awkwardly against the group's documented English-speaking social-engineering tradecraft; treat it as a single-source claim.

What Was Taken

Record counts vary by source and should be quoted as a range. Odido's own figure, cited by Security Affairs, Hackify and Geek Feed, is 6.2 million current and former customers. Security Affairs frames it as "more than six million." Data Security Wiki puts it at approximately 6.39 million. ShinyHunters claims data on over 8 million individuals (S1). The gap between the victim's 6.2 million and the attackers' 8 million is itself an intelligence signal, and typical of extortion crews inflating a haul to increase pressure.

On field types the sources are consistent. Odido confirmed the theft of full name, address and city of residence, mobile number, customer number, email address, IBAN bank account number, date of birth, and identity document details including passport or driving licence number and validity dates. Hackify notes the affected system also held records for Ben customers but not Simpel customers.

S1 adds that the leaked records include payment history, whether a customer has a guardian, and whether they have defaulted on their contract. That detail appears in only one lower-tier source and goes beyond what Odido has acknowledged, so it should be held as a claim rather than a confirmed fact. S1 also reports that the attackers have so far withheld most phone numbers and email addresses while stating an intent to publish progressively more sensitive material, a staged-escalation pattern consistent with the daily-release threat.

Odido has been firm about the exclusions: no Mijn Odido account passwords, no call detail records, no location data, no billing or invoice details, and no scans of identity documents. That boundary matters, but it does not blunt the impact. Name plus date of birth plus IBAN plus passport number is a complete identity-theft kit on its own.

Why It Matters

Hackify's research supplies the clearest evidence of downstream harm. Two of its staff appeared in the dataset using per-service unique email aliases given only to Odido and Tele2, which makes every subsequent phishing email on those addresses traceable to this one breach. In the 150 days after publication they received 61 phishing emails, 32 on the Odido alias and 29 on the Tele2 alias. That is a measured, attributable conversion rate from breach to targeted phishing, and it is the number defenders should carry into their own risk modelling. Leaked telecom identity data does not sit dormant; it is operationalised within weeks.

The second point is structural. ShinyHunters is not an outlier campaign but a sustained programme. Microsoft documented overlapping tradecraft across campaigns from mid-2025 through mid-2026 hitting tenants in retail, education and manufacturing. Health-ISAC issued a 24 July advisory warning of a rising tempo of successful ShinyHunters attacks against healthcare and medtech organisations. A Dutch telecom, a hospital group and a manufacturer are all the same target from this crew's perspective: an SSO tenant with a helpdesk attached.

Third, the extortion model has shifted. The drip-feed is designed to keep a victim under continuous public pressure and to give regulators, customers and press a fresh news cycle every 24 hours. Refusing to pay, which Hackify reports Odido did, does not end the exposure; it changes the shape of it.

The Attack Technique

The entry point was social engineering, not a software vulnerability. Dutch police, in a press release reported by Geek Feed, ITdaily, Security Affairs and Data Security Wiki, said a Dutch-speaking man telephoned Odido customer service shortly before the hack posing as an internal IT employee. The company was then misled via phishing, after which the data theft occurred. That call is now the investigation's central lead, and police have indicated the caller's voice could be made public if necessary. Stan Duijf, Head of Operations at the National Investigation and Interventions Unit, said traces were secured at several points during the investigation and that the work will take at least several more months. The High Tech Crime Team is running the case under the National Public Prosecution Service.

Microsoft's analysis, the strongest primary technical source available here, describes the wider playbook. Two intrusion paths dominate: vishing aimed at obtaining OAuth consent, and supply chain compromise through trusted workflows and integrations such as Salesloft and Gainsight. Both yield inherited user and application privileges, which let the actor enumerate and query CRM records while evading conventional authentication detections and maintaining persistence. Microsoft is explicit that this is not a Salesforce vulnerability; it is abuse of trusted OAuth relationships.

BleepingComputer, reporting Health-ISAC's advisory, fills in the identity side. The chain starts with vishing against employees or helpdesk staff to trigger a password reset, an MFA method change, or enrolment of a new device. With that account in hand, the actor logs into the organisation's Okta, Microsoft Entra or Google SSO dashboard, which conveniently enumerates every SaaS application the user can reach: Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive. One compromised identity becomes a springboard across the entire cloud estate. BleepingComputer has previously reported the group using custom phishing kits purpose-built for voice-based operations.

Odido's "customer contact system" fits this pattern precisely. A single helpdesk-mediated identity compromise, followed by mass query of a CRM-class datastore.

What Organizations Should Do

  1. Harden the helpdesk against voice. Treat any inbound request to reset a password, change an MFA method, or enrol a new device as high risk regardless of how convincing the caller sounds. Require out-of-band verification through a channel the caller did not initiate, such as a callback to the number of record or manager attestation. The Odido lead is a Dutch-speaking man who sounded like internal IT; fluency and plausibility are the attack.
  2. Audit every OAuth-connected application. Inventory all connected apps and integrations across Salesforce, Entra and Google Workspace, revoke tokens and consents that are unused or over-scoped, and disable end-user consent for anything not on an approved list. Microsoft's guidance is specific: monitor OAuth-connected applications, validate third-party integrations and review configurations.
  3. Enable and actually watch SaaS event telemetry. Turn on Salesforce event monitoring. Microsoft worked with Salesforce to improve telemetry granularity in Defender for Cloud Apps, adding near-real-time detection, connected application attribution and expanded permission insight. That telemetry only helps if someone is alerting on it.
  4. Alert on bulk-query behaviour, not just logins. These intrusions succeed by looking authenticated. Baseline normal CRM export and query volumes per user and per integration, and alert on anomalous record counts, unusual API clients, and off-hours mass reads.
  5. Constrain third-party integration blast radius. Salesloft and Gainsight were named compromise vectors. Scope integration service accounts to the minimum object and field set required, rotate their credentials on a schedule, and require the vendor to notify you of their own incidents.
  6. Plan for the extortion phase before it arrives. Decide in advance who owns the pay-or-refuse decision, how you notify regulators under GDPR timelines, and how you communicate during a multi-day drip-feed. Odido reportedly refused to pay and is now managing a serialised public release.
  7. Warn affected customers about the follow-on phishing. Hackify's 61 emails in 150 days is the realistic downstream volume. Tell customers explicitly that with their IBAN, date of birth and ID number in criminal hands, convincing "your bank/telco" lures will follow, and that legitimate contact will never request account credentials or new payment mandates.

Sources: ShinyHunters Leaks 1 Million More Odido Customer Records - Data Bre... | Defending SaaS-based applications against ShinyHunters OAuth abuse... | Dutch Nationals Suspected in Odido Hack That Exposed ... | Health-ISAC warns of rising ShinyHunters data theft attacks on heal... | Are Dutch hackers behind the Odido hack? - ITdaily | Odido data breach: 150 days and 61 phishing emails later Hackify | Vishing Call Becomes Key Lead in Massive Odido Cyberattack - Data S... | Police suspects Dutch hackers were involved in Odido breach - Geek...