Vulnerabilities

Dutch Hackers Implicated in Odido Breach

July 13, 2026 12:15 · 8 min read
Dutch Hackers Implicated in Odido Breach

The Dutch National Police (Politie) has found strong indications that Dutch hackers were involved in a February breach at the telecommunications provider Odido. This breach affected 6.2 million customers, with exposed information including full names, addresses, mobile numbers, and identification details.

Odido Breach Details

According to the police, a Dutch-speaking man posed as Odido's IT employee in a telephone conversation with the company's customer service shortly before the hack. The company was then misled through phishing, after which the data theft took place. The police stated that this type of investigation is often complex and takes time, but cybercriminals are also vulnerable and leave traces.

Stan Duijf, the head of operations at the National Investigation and Interventions Unit, added that traces have been secured at several times during the investigation into the hack at Odido. The research team continued to work on the investigation, following the complex trail of evidence.

Odido's Response to the Breach

Odido disclosed the breach on February 12, stating that the attackers accessed its customer contact system on February 7 and downloaded the personal data of many of its users. The company told local media that the resulting data breach affected 6.2 million customers and that the threat actors reached out to say they had stolen millions of user records.

The exposed information varies per customer and may include a combination of full name, address and city of residence, mobile number, customer number, email address, IBAN (bank account number), date of birth, and some identification details (passport or driver's license number and validity). However, Odido stated that no call details, location data, billing data, scans of identity documents, or Mijn Odido passwords were exposed during the incident.

ShinyHunters' Involvement

The ShinyHunters extortion gang claimed responsibility for the breach on its dark web leak site, releasing an 88GB archive containing over 15 million records, including data the company had already disclosed as exposed in the attack. ShinyHunters has been behind widespread vishing campaigns targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, impersonating IT support staff to trick targets' employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.

After breaching corporate SSO accounts, the threat actors steal data from connected SaaS applications, including Microsoft 365, Google Workspace, Salesforce, SAP, Slack, Zendesk, Dropbox, Adobe, Atlassian, and others. The cybercrime group has been linked to a growing number of breaches involving companies such as Google, Cisco, PornHub, the online dating giant Match Group, the European Commission, Rockstar Games, and the McGraw-Hill edtech giant.

Security Implications

The Odido breach highlights the importance of cybersecurity and the need for companies to protect their customers' data. The breach also underscores the vulnerability of single sign-on (SSO) accounts and the need for robust security measures to prevent such attacks. As the police continue to investigate the breach, Odido customers are advised to remain vigilant and monitor their accounts for any suspicious activity.

Security teams should log all successful attacks and alert on potential threats to prevent breaches. The Picus whitepaper shows how breach and attack simulation tests can help identify vulnerabilities and prevent threats from slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free