Cyber & AI intelligence
Wasteland.
Briefs indexed2992
Issues30
Published Mondays07:30 CT
▣ Breach ODIDO-SHINYHUNTERS 2026-10-03

Odido: ShinyHunters Says Leak Site Moved, Not Seized

"ShinyHunters, the extortion group that claimed the February 2026 theft of customer data from Dutch telecom Odido, says its leak site has moved to a new address and was not taken down. The group told Dutch broadcaster…"

ShinyHunters, the extortion group that claimed the February 2026 theft of customer data from Dutch telecom Odido, says its leak site has moved to a new address and was not taken down. The group told Dutch broadcaster BNR that the move followed repeated denial-of-service attacks by "rivals" and problems with the data centres hosting its infrastructure, NL Times reports. This is a follow-up to the earlier breach, not a new incident. Reported victim counts vary. Several outlets give "at least" or "more than" 6 million customers. Mirage Security, citing Krebs on Security, puts it at more than 6.2 million. The Daily Tech Feed and CyberWebSpider report that Odido itself confirmed about 6.39 million current and former customers. All eight sources for this brief are secondary reporting. None of them is a direct statement from Odido, Dutch police or a regulator, so figures credited to those parties are as relayed by the press.

What Happened

The leak site. Around the time Dutch police arrested a suspected ShinyHunters leader in mid-September, the group's leak site went offline. Several news organisations reported that it had been taken down. ShinyHunters now says it simply moved. The group also says a message announcing maintenance "was somehow lost," and denies any link between the outage and the arrest (NL Times). Its claims about rival DDoS attacks and hosting problems have not been independently verified.

The arrest. Dutch authorities detained Pepijn van der S., an Amsterdam-based internet security professional who police suspect is one of ShinyHunters' leaders. The sources disagree on some details:

His record. According to AD, Van der S. was sentenced in 2023 to four years in prison for hacking and extorting companies, and had been free since early 2026. NL Times adds that the conviction also covered blackmail and money laundering.

Separate allegations. Prosecutors have confirmed allegations that he tried to solicit two murders, based on evidence found on his seized laptop. Prosecutors treat these as separate from the cybercrime investigation (NL Times).

ShinyHunters' response. The group says it has no formal connection to Van der S. and does not consider him a talented hacker. Police have not said publicly that he is the man heard on the recorded Odido call.

Escalation. Krebs' sources say ShinyHunters stepped up activity after the arrest, including a claimed breach of the FBI's job application portal (apply.fbijobs.gov) that reportedly exposed data on more than 5,000 FBI personnel. The FBI confirmed that the site had been compromised (NL Times, Mirage). According to NL Times, the FBI has attributed attacks on more than 140 organisations since last year to ShinyHunters, involving data worth at least US$70 million. The group then demanded that the FBI amend or withdraw those statements.

What Was Taken

Accounts of the volume differ:

Data types reported: full names, home addresses, dates of birth, phone numbers, email addresses, customer numbers, bank account (IBAN) details and identification numbers. CyberWebSpider reports that Odido says passwords and billing data were not taken. ShinyHunters claims otherwise.

Extortion timeline: ShinyHunters demanded a ransom of €1 million, according to CyberWebSpider. Odido refused. The group then published the data in stages from 26 February to 1 March, which was followed by a reported surge in phishing aimed at affected customers.

Why It Matters

The Attack Technique

The sources broadly agree on how the attackers got in:

  1. Vishing. On 5 and 6 February, a Dutch-speaking man who used specific English-language IT terminology called Odido customer service. He posed as a colleague from the IT department and described an urgent internal problem (The Daily Tech Feed, CyberWebSpider, DarkDotWeb).
  2. Credential harvesting. He directed the employee to a fake Odido login page, where the employee entered a username and password.
  3. MFA relay. The attacker then obtained the verification code needed to complete authentication.
  4. CRM access. With those credentials, the attacker logged into Odido's Salesforce-based CRM.
  5. Bulk export. On 7 and 8 February, about 90 GB was exfiltrated through legitimate Salesforce APIs, reportedly without triggering alerts.

The investigation. Police first asked the caller to come forward in July. When he did not, they broadcast part of the recording on the TV programme Opsporing Verzocht on 7 September. A voice expert concluded the voice was genuine, not AI-generated (DarkDotWeb). ShinyHunters then told Dutch media that the caller is a member of the group and that it had arranged a criminal defence lawyer for him (DarkDotWeb, NL Times).

Mirage rates the operation "medium sophistication." Its effectiveness came from convincing knowledge of Odido's internal terminology, not from technical tooling.

What Organizations Should Do

  1. Verify inbound IT calls through a separate channel. Helpdesk and customer support staff should never log in, reset credentials or read out codes because of an unsolicited call. Require a callback to a known internal number, or a ticket number from the ITSM system.
  2. Use phishing-resistant MFA. Move privileged and CRM users from OTP and push codes to FIDO2/WebAuthn passkeys or hardware keys, which a fake login page cannot relay.
  3. Watch SaaS API activity, not just logins. Baseline normal Salesforce and other CRM API volumes per user. Alert on bulk exports, unusual query patterns and large report downloads, and cap export permissions for frontline roles.
  4. Apply least privilege to support staff. Customer service accounts should not be able to access, or bulk-query, millions of records including IBANs and ID numbers.
  5. Enforce data retention limits. Former-customer records kept "up to two years" expanded the blast radius. Purge or tokenise data you no longer need.
  6. Prepare breach communications in advance. Early, inaccurate scoping, such as telling a business client only administrators were affected, damages trust. Communicate only what is verified and update quickly. Warn affected customers about follow-on phishing that uses the leaked data.

Sources: ShinyHunters: Hackers behind massive Odido data theft say website w... | Dutch authorities arrest suspected ShinyHunters member in Odido hac... | ShinyHunters Talked Into Odido via Spoofed Login Mirage Threat Wat... | Nederlander (23) opgepakt in onderzoek naar hackers achter Odido N... | ShinyHunters Offers Lawyer After Odido Hack Voice Released – DarkDo... | ShinyHunters’ Social Engineering Exploit Leaks 6M Odido Records – T... | Security (b)log: Oliedommer | Dutch Telecom Breach via Phone Scam Tech News