Dutch Police Say Local Hackers Helped Pull Off the Odido Breach That Exposed 6.2 Million Customers

A phone call to customer service, a fake IT worker, and a phishing page: how criminals allegedly walked out with data on nearly every Odido subscriber.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration for the story: Dutch Police Say Local Hackers Helped Pull Off the Odido Breach That Exposed 6.2 Million
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The Dutch National Police said on Thursday it has strong indications that Dutch nationals helped carry out the February breach at telecoms provider Odido.
  • Odido disclosed on 12 February that attackers reached its customer contact system on 7 February and stole personal data on 6.2 million customers.
  • Investigators traced a phone call in which a Dutch-speaking man posed as an Odido IT employee shortly before the break-in.
  • The extortion crew ShinyHunters claimed the attack and posted an 88GB archive with more than 15 million records on its dark web leak site.
  • Exposed fields may include names, addresses, phone numbers, email addresses, IBAN bank numbers, dates of birth and identity document numbers.

Odido is one of the largest phone and internet companies in the Netherlands. In February, someone walked out with the personal details of most of its customers. This week, Dutch police said they think they know part of the answer: at least some of the people behind the attack were Dutch themselves.

The method was almost embarrassingly old-school. Someone rang Odido's customer service line, said he worked in the company's IT department, and spoke Dutch well enough to be believed. That call, police say, was the opening move.

What came next was phishing, where criminals set up fake login pages to trick staff into typing their passwords. Once a real Odido employee handed over credentials, the attackers walked into the customer contact system and started downloading.

"This type of investigation is often complex and takes time, but cybercriminals are also vulnerable and leave traces," said Stan Duijf, head of operations at the National Investigation and Interventions Unit. Investigators have been picking up those traces for months.

What data was actually taken?

Odido says the stolen file varies by customer, but it can include full name, home address, mobile number, customer number, email address, IBAN (the bank account number format used across Europe), date of birth, and some identity document numbers such as passport or driving licence numbers along with their expiry dates.

Call records, location data, billing details, ID document scans and Mijn Odido portal passwords were not in the stolen set. That still leaves plenty for fraud. A name, address, date of birth and a bank account number is a starter kit for impersonation and the scam calls that reliably follow every big telecoms breach.

Should Odido customers be worried?

Yes, but the useful response is boring, not panicked. Assume your details are out there. Treat any call or text claiming to come from Odido, your bank or the tax office with suspicion, especially if it pushes you to click a link or read out a code.

Banks in the Netherlands won't ask you to move money to a "safe account." Odido won't ask for your password. If you're unsure, hang up and dial a number you find yourself.

Who are ShinyHunters?

Odido hasn't officially named the culprits. The extortion group ShinyHunters posted the company on its dark web leak site, releasing an 88GB archive with over 15 million records, first reported by BleepingComputer.

ShinyHunters runs vishing campaigns, which is phishing done over the phone, impersonating IT support to talk employees into surrendering their login and their multi-factor authentication code (the extra one-time code meant to keep accounts safe even if a password leaks). We covered the same playbook in July when ShinyHunters broke into Medtronic and walked away with records on 3.8 million patients.

Once inside, the group pulls data from connected business apps: Microsoft 365, Google Workspace, Salesforce, Zendesk and others. They've been linked to intrusions at Google, Cisco, Match Group and the European Commission, and were behind breaches at more than a dozen Snowflake customers last year.

The thing worth watching now isn't the technical sophistication, because there wasn't much. It's how little friction stood between one convincing phone call and 6.2 million customer records. Dutch police being able to identify local suspects quickly is the one encouraging detail here, and even that took months.

© 2026 Threat Vectr