A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big Dutch telecom company Odido and its budget brand Ben were the latest victims of ShinyHunters. This hacking group is known for using tricks to get inside companies instead of complex methods.
The attack revealed the personal information of over six million customers, and Dutch police have now shared the suspected caller’s real voice to try to identify him. A Dutch-speaking man called Odido’s customer service on February 5 and 6. He used specific English IT terms and pretended to be an IT colleague.
He told the worker there was a problem that needed fixing quickly. The worker, not knowing better, gave him access to what looked like a real internal system but was actually a trick created by the attackers.
The caller got a username, password, and a multi-factor authentication token in that one call, breaking through one of Odido’s main security protections. The attackers used the stolen login details to get into Odido’s Salesforce CRM system, which is used to track and manage customer interactions.
Massive Data Breach
Two days later, about 90 GB of data from around 15 million rows was taken quietly using regular Salesforce APIs. This means the data was exported in a way that looked normal and didn’t raise alarms at all.
Odido has confirmed that someone accessed its customer contact system without permission on February 7 and 8. They stopped the intrusion right after they found out.
Odido’s official update says about 6.39 million people were affected. This includes both active and inactive Odido and Ben customers. Earlier guesses from the company and media said it was between 6.1 million and 6.2 million. ShinyHunters claimed to have taken nearly 21 million records, which probably includes duplicates and business info along with customer details.
The stolen dataset is said to have full names, home addresses, phone numbers, email addresses, birth dates, customer numbers, IBAN bank account info, and ID numbers like passports and driver’s licenses.
Odido said no account passwords, call records, or billing info were stolen, but ShinyHunters disagreed, saying plain text passwords and internal files were included. Have I Been Pwned later confirmed about 6 million unique email addresses were shared in four different data leaks.
ShinyHunters reportedly demanded a ransom of around one million euros to prevent publication of the stolen dataset. Odido refused to pay, a decision the company later defended publicly, and the group responded by releasing the data in stages starting February 26, ultimately publishing the complete cache by March 1.
The effects were quick. Cybersecurity experts watched two email names linked to Odido and Tele2. They saw 61 phishing emails sent within 150 days after the leak was public. This shows how fast stolen personal data is used for fraud and vishing scams.
Dutch police also added affected customers’ email addresses to their “Check je hack” tool, allowing individuals to verify whether their information was part of the stolen dataset.
The investigation is led by the Landelijk Parket. The High Tech Crime Team from the National Police is doing the work. It started soon after the breach was made public.
In July 2026, investigators announced they had found “strong indications” that Dutch nationals were involved, centering on the phone call placed just before the hack. Police publicly urged the caller to come forward voluntarily, warning that his voice could otherwise be released.
When nobody answered that call for help, Dutch police played the full recording on the true-crime show Opsporing Verzocht on Monday, September 7, at 21:15 on NPO2. A voice expert working with the police said the recording is a real human voice, not made by AI. The expert noted that the caller spoke Dutch, showed good ICT knowledge, used English technical words on purpose, and had a unique speech habit with the Dutch word “hoor.” Now, authorities want the public to send tips through politie.nl/odido, the anonymous tip line Meld Misdaad Anoniem, or the Telegram channel @Veiligmelden.
Security experts have noted three big mistakes that let one phone call lead to such a huge breach: no callback checks at the helpdesk, too much access that allowed one hacked account to download the whole customer database, and poor monitoring that couldn’t identify a 90 GB data transfer as suspicious.
InfoSecBulletin Cybersecurity for mankind
