ShinyHunters, the extortion group that claimed the February 2026 theft of customer data from Dutch telecom Odido, says its leak site has moved to a new address and was not taken down. The group told Dutch broadcaster BNR that the move followed repeated denial-of-service attacks by "rivals" and problems with the data centres hosting its infrastructure, NL Times reports. This is a follow-up to the earlier breach, not a new incident. Reported victim counts vary. Several outlets give "at least" or "more than" 6 million customers. Mirage Security, citing Krebs on Security, puts it at more than 6.2 million. The Daily Tech Feed and CyberWebSpider report that Odido itself confirmed about 6.39 million current and former customers. All eight sources for this brief are secondary reporting. None of them is a direct statement from Odido, Dutch police or a regulator, so figures credited to those parties are as relayed by the press.
What Happened
The leak site. Around the time Dutch police arrested a suspected ShinyHunters leader in mid-September, the group's leak site went offline. Several news organisations reported that it had been taken down. ShinyHunters now says it simply moved. The group also says a message announcing maintenance "was somehow lost," and denies any link between the outage and the arrest (NL Times). Its claims about rival DDoS attacks and hosting problems have not been independently verified.
The arrest. Dutch authorities detained Pepijn van der S., an Amsterdam-based internet security professional who police suspect is one of ShinyHunters' leaders. The sources disagree on some details:
- Arrest date: NL Times (2 October) says police confirmed an arrest on 15 September. Brian Krebs' sources, cited by NL Times on 28 September, said "around September 16."
- Age: NL Times and AD give 23 in their 28 September reports. NL Times gives 24 in its 2 October piece.
- Police communication: On 28 September, AD reported that police declined to comment, which it called unusual. By NL Times' 2 October account, police had since confirmed the arrest publicly.
His record. According to AD, Van der S. was sentenced in 2023 to four years in prison for hacking and extorting companies, and had been free since early 2026. NL Times adds that the conviction also covered blackmail and money laundering.
Separate allegations. Prosecutors have confirmed allegations that he tried to solicit two murders, based on evidence found on his seized laptop. Prosecutors treat these as separate from the cybercrime investigation (NL Times).
ShinyHunters' response. The group says it has no formal connection to Van der S. and does not consider him a talented hacker. Police have not said publicly that he is the man heard on the recorded Odido call.
Escalation. Krebs' sources say ShinyHunters stepped up activity after the arrest, including a claimed breach of the FBI's job application portal (apply.fbijobs.gov) that reportedly exposed data on more than 5,000 FBI personnel. The FBI confirmed that the site had been compromised (NL Times, Mirage). According to NL Times, the FBI has attributed attacks on more than 140 organisations since last year to ShinyHunters, involving data worth at least US$70 million. The group then demanded that the FBI amend or withdraw those statements.
What Was Taken
Accounts of the volume differ:
- Customers affected: "at least 6 million" (NL Times), "more than 6 million" (DarkDotWeb), "more than 6.2 million" (Mirage/Krebs), and about 6.39 million per Odido's own confirmation (as reported by The Daily Tech Feed and CyberWebSpider). The Daily Tech Feed says earlier estimates were 6.1 to 6.2 million.
- Raw volume: about 90 GB and roughly 15 million database rows (The Daily Tech Feed, CyberWebSpider). ShinyHunters claimed up to 21 million records. The Daily Tech Feed suggests that figure likely includes metadata and duplicates.
- Scope: customers of both Odido and its budget brand Ben were affected, including former customers. A security blogger who was a T-Mobile customer until 2019 reports receiving a breach notice on 13 February. The notice said Odido keeps contact details for up to two years after a contract ends. The same blogger reports that Odido first told a business client that only administrator accounts on its business portal were affected. Data on several thousand of that client's employees later turned out to be exposed.
Data types reported: full names, home addresses, dates of birth, phone numbers, email addresses, customer numbers, bank account (IBAN) details and identification numbers. CyberWebSpider reports that Odido says passwords and billing data were not taken. ShinyHunters claims otherwise.
Extortion timeline: ShinyHunters demanded a ransom of €1 million, according to CyberWebSpider. Odido refused. The group then published the data in stages from 26 February to 1 March, which was followed by a reported surge in phishing aimed at affected customers.
Why It Matters
- Social engineering got past MFA. One phone call reportedly defeated Odido's multi-factor authentication. This was not a technical exploit, and the attacker never needed malware.
- The theft blended in. Data was reportedly pulled through legitimate Salesforce APIs using valid credentials, so it looked like normal business traffic and did not trigger alerts.
- The group is still active. Despite an arrest, ShinyHunters is publicly taunting authorities, offering members legal and financial support (DarkDotWeb, NL Times) and claiming new victims.
- The arrest does not end the threat. Leak infrastructure that relocates instead of disappearing means data already stolen stays in circulation and the extortion operation keeps running.
- Wider reach. ShinyHunters reportedly works with Scattered Spider and Lapsus$ (AD). AD says the group has hacked at least 90 companies. The FBI's figure, as reported by NL Times, is more than 140 organisations. AD links the group to earlier claims involving AT&T (73 million records claimed in 2021), Ticketmaster (2024) and Pornhub (200 million premium accounts claimed, including 1.5 million Dutch users). These links are as reported by AD and have not been independently confirmed here.
- Downstream risk for Odido customers. A dataset combining IBANs, dates of birth and ID numbers is well suited to fraud and to convincing phishing.
The Attack Technique
The sources broadly agree on how the attackers got in:
- Vishing. On 5 and 6 February, a Dutch-speaking man who used specific English-language IT terminology called Odido customer service. He posed as a colleague from the IT department and described an urgent internal problem (The Daily Tech Feed, CyberWebSpider, DarkDotWeb).
- Credential harvesting. He directed the employee to a fake Odido login page, where the employee entered a username and password.
- MFA relay. The attacker then obtained the verification code needed to complete authentication.
- CRM access. With those credentials, the attacker logged into Odido's Salesforce-based CRM.
- Bulk export. On 7 and 8 February, about 90 GB was exfiltrated through legitimate Salesforce APIs, reportedly without triggering alerts.
The investigation. Police first asked the caller to come forward in July. When he did not, they broadcast part of the recording on the TV programme Opsporing Verzocht on 7 September. A voice expert concluded the voice was genuine, not AI-generated (DarkDotWeb). ShinyHunters then told Dutch media that the caller is a member of the group and that it had arranged a criminal defence lawyer for him (DarkDotWeb, NL Times).
Mirage rates the operation "medium sophistication." Its effectiveness came from convincing knowledge of Odido's internal terminology, not from technical tooling.
What Organizations Should Do
- Verify inbound IT calls through a separate channel. Helpdesk and customer support staff should never log in, reset credentials or read out codes because of an unsolicited call. Require a callback to a known internal number, or a ticket number from the ITSM system.
- Use phishing-resistant MFA. Move privileged and CRM users from OTP and push codes to FIDO2/WebAuthn passkeys or hardware keys, which a fake login page cannot relay.
- Watch SaaS API activity, not just logins. Baseline normal Salesforce and other CRM API volumes per user. Alert on bulk exports, unusual query patterns and large report downloads, and cap export permissions for frontline roles.
- Apply least privilege to support staff. Customer service accounts should not be able to access, or bulk-query, millions of records including IBANs and ID numbers.
- Enforce data retention limits. Former-customer records kept "up to two years" expanded the blast radius. Purge or tokenise data you no longer need.
- Prepare breach communications in advance. Early, inaccurate scoping, such as telling a business client only administrators were affected, damages trust. Communicate only what is verified and update quickly. Warn affected customers about follow-on phishing that uses the leaked data.
Sources: ShinyHunters: Hackers behind massive Odido data theft say website w... | Dutch authorities arrest suspected ShinyHunters member in Odido hac... | ShinyHunters Talked Into Odido via Spoofed Login Mirage Threat Wat... | Nederlander (23) opgepakt in onderzoek naar hackers achter Odido N... | ShinyHunters Offers Lawyer After Odido Hack Voice Released – DarkDo... | ShinyHunters’ Social Engineering Exploit Leaks 6M Odido Records – T... | Security (b)log: Oliedommer | Dutch Telecom Breach via Phone Scam Tech News