Dutch telecom provider Odido and its budget subsidiary Ben reported that a February 2026 breach exposed data on approximately 6.39 million active and former customers. ShinyHunters allegedly obtained an employee's username, password, and MFA token through a Dutch-language social-engineering call to the helpdesk, then used legitimate Salesforce APIs to export about 90 GB of customer-contact data—roughly 15 million rows—from the company’s CRM environment.
The group reportedly published the stolen data after Odido refused a ransom demand of about €1 million. Dutch police are investigating possible Dutch involvement and released a recording of the alleged caller’s voice to the public, seeking information that could identify the suspect.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Dutch police released the full recording of the alleged social-engineering caller on Opsporing Verzocht, seeking public assistance identifying the voice. A police-consulted voice expert assessed the recording as a genuine human voice rather than AI-generated speech.
Dutch investigators said they had strong indications that Dutch nationals were involved in the Odido intrusion.
ShinyHunters reportedly completed publication of the stolen Odido data cache. Have I Been Pwned later confirmed roughly six million unique email addresses appeared across four releases.
After Odido declined the reported ransom demand, ShinyHunters allegedly began releasing the stolen customer data. Odido said approximately 6.39 million active and former Odido and Ben customers were affected.
Odido confirmed unauthorized access to its customer-contact system on February 7 and 8. The attackers allegedly used harvested credentials to access Salesforce and exfiltrate about 90 GB of data across roughly 15 million rows through legitimate APIs.
A Dutch-speaking caller impersonating an IT colleague contacted Odido's customer-service helpdesk on February 5 and 6, allegedly causing an employee to submit a username, password, and MFA token to an attacker-controlled credential-harvesting system.
ShinyHunters reportedly demanded approximately €1 million to avoid disclosure of the stolen Odido and Ben customer data, and Odido refused the demand.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.