ShinyHunters’ Social Engineering Exploit Leaks 6M Odido Records

In early February 2026, the hacker group known as ShinyHunters gained access to over 6 million customer records from Dutch telecom firm Odido and its budget subsidiary Ben via a single phone call. The breach has been labeled one of the largest in Dutch history, highlighting the risks of social engineering over modern technical defenses. Authorities have since made the caller’s voice public as part of their investigation.

How the Attack Was Carried Out

On February 5 and 6, an individual speaking Dutch—fluent in English technical terms—called Odido’s customer support, posing as an internal IT department staffer. The caller convinced the agent of an urgent issue and was granted access to what the agent believed was a genuine internal system. However, the system was a credential-harvesting setup. In that single interaction, the attacker acquired a username, a password, and a multi-factor authentication (MFA) token, effectively bypassing key security layers. With those credentials, the attacker redirected into Odido’s Salesforce-based customer relationship management platform.

Data Exfiltration and Fallout

By February 7 and 8, the attacker quietly extracted around 90 gigabytes of data, corresponding to roughly 15 million database rows, using legitimate Salesforce APIs. Because the extraction used authorized channels, the traffic mirrored normal operations and did not trigger immediate alarms. Not long afterward, Odido confirmed unauthorized access, distinguishing that about 6.39 million individuals—both active and inactive customers—were affected. Earlier numbers floated between 6.1 million and 6.2 million, while ShinyHunters claimed the haul contained up to 21 million records; that larger figure likely includes internal metadata and duplicates.

Sensitive Data & Disputed Claims

The compromised information reportedly contained full names, addresses, dates of birth, phone numbers, email addresses, customer IDs, bank account (IBAN) details, and identification numbers such as passports and driver’s licenses. Odido stated that no passwords, billing data, or phone logs were exposed. ShinyHunters, in contrast, asserted plaintext passwords and internal corporate files were also among the stolen data. The independent site Have I Been Pwned confirmed that about 6 million unique email addresses appeared across four data releases tied to the breach.

Ransom Refusal & Aftermath

ShinyHunters reportedly demanded around one million euros in ransom to prevent publication of the data. Odido stood firm and refused to pay. Between February 26 and March 1, the group released the stolen dataset in stages, culminating in the full leak. In the breach’s wake, researchers tracked 61 phishing emails over the following 150 days sent to aliases tied to Odido and a rival carrier. The leak’s aftermath also prompted Dutch authorities to add exposed addresses to a public tool used for people to check if they are affected.

Investigation and the Recording

Investigators believe the suspect is a Dutch national who placed the crucial phone call. In July 2026, strong indications pointing to local involvement were flagged. The police appealed for the caller to step forward. When there was no response, they aired the caller’s voice recording on September 7 during a televised true-crime program. A forensic voice expert confirmed the audio is from a real person—not AI generated—and noted characteristics like use of ICT jargon, fluency in both languages used, and the inclusion of the Dutch filler “hoor.” The public has been urged to submit tips through official channels.

Lessons & Systemic Weaknesses

Security analysts identified three failures that enabled the breach: helpdesk processes lacked callback or off-band verification, a single compromised account had overly broad data export access, and monitoring did not flag an anomalous 90 GB data transfer despite its volume. ShinyHunters has used nearly identical phone-based social engineering tactics in breaches at more than 100 organizations globally—including big targets like SoundCloud, Crunchbase, and Betterment—often bypassing single sign-on protections without traditional technical exploits.

The Odido breach underscores the truth that powerful tools and defenses offer little safety if human controls are weak. As companies ramp up defenses against malware, ransomware, and phishing, the Odido case shows that a single successful impersonation—one phone call—can undermine everything. What to watch: reforms in helpdesk protocol, stricter MFA practices, and smarter detection systems that can spot anomalous API behavior—even when the traffic looks ordinary.