ShinyHunters has claimed responsibility for breaching Dutch telecommunications provider Odido (and brand BEN) and stealing a much larger dataset than the company initially indicated. Odido previously disclosed that attackers accessed its customer contact system and downloaded customer data, reporting the incident to the Dutch Data Protection Authority, cutting off attacker access, and bringing in external incident-response support. Odido said the exposed data varied by customer and could include identifiers and contact details such as name, address, mobile number, customer number, email address, IBAN, date of birth, and some ID details (e.g., passport/driver’s license numbers and validity), while stating that Mijn Odido passwords, call/location/data/billing details, and scans of identity documents were not exposed.
ShinyHunters subsequently listed Odido on its leak site and alleged theft of ~21 million records tied to ~8 million customers, asserting Odido downplayed the scope. The gang’s claims also include highly sensitive elements—most notably plaintext passwords—and additional materials such as internal corporate documents and source code, which (if accurate) would materially increase risks of credential stuffing/account takeover, identity fraud, and follow-on intrusion. At the time of reporting, the expanded dataset details (including plaintext passwords and source code) were presented as attacker claims rather than independently confirmed by Odido.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On March 26, the Dutch Data Protection Authority said it had opened a formal investigation into whether Odido kept customer personal data longer than legally necessary, after complaints from people who said their data was stolen despite no longer being customers. The authority and the Rijksinspectie Digitale Infrastructuur were also examining whether security around Odido’s customer systems had been adequate.
By March 25, the Dutch CJIB and fraud-reporting organizations were handling a surge of reports about fake traffic-fine emails demanding payment within 24 hours. Authorities and researchers said a connection to the Odido breach was plausible because the leaked personal data could be used to make the phishing messages more convincing.
On March 1, ShinyHunters released what it described as the full Odido customer dataset for free online, culminating a series of four leak-site releases. Reporting said the final dump brought the exposed total to about 6.1 million unique email addresses and was characterized as one of the largest data leaks in the Netherlands.
As the leaks escalated, Odido CEO Søren Abildgaard said the company would not negotiate with the extortionists, in line with Dutch police guidance against ransom payments. Odido also offered affected customers a free 24-month digital security package and warned them to watch for phishing and fraud.
The Odido breach was added to Have I Been Pwned on February 26, making the exposed dataset searchable for affected users. Reporting said the breach involved approximately 688,100 customer accounts in the initial HIBP entry.
After Odido refused to negotiate, ShinyHunters started a staged leak campaign, publishing about 1 million records on February 26 and another roughly 1 million early the next day. The leaked data reportedly included names, addresses, emails, phone numbers, IBANs, and identity document numbers.
After ShinyHunters' public claim, Odido confirmed the cyberattack but rejected assertions that plaintext passwords, social security numbers, billing data, call details, location data, or scans of identity documents were exposed. The company maintained the breach was limited to data in the customer contact system and that core telecom services were unaffected.
By February 24, ShinyHunters added Odido to its dark web leak site, claimed responsibility for the intrusion, and threatened to leak stolen data unless the company paid more than €1 million. The group alleged it stole roughly 21 million records tied to about 8 million customers, including sensitive personal, financial, and internal corporate data.
On February 12, Odido publicly disclosed the breach, said 6.2 million current and former customers were affected, and published an incident update and FAQ. The company also reported the incident to the Dutch Data Protection Authority and began notifying impacted customers by email or SMS.
During the intrusion, attackers accessed and downloaded customer personal data from Odido's contact system. Odido later said the exposed data could include contact details, IBANs, dates of birth, and some identity document details, but not passwords, call records, billing data, or ID scans.
Odido detected unusual activity and unauthorized access to its customer contact management system over the weekend of February 7–8, 2026. The company says it terminated the access quickly and began incident response measures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
nos.nl
Open sourcenos.nl
Open sourcenrc.nl
Open sourceosintteam.blog
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.