Dutch Police Suspect Local Hackers Behind Massive Odido Data Breach
In a significant development in the ongoing investigation into the massive Odido data breach, Dutch police have revealed that they have found strong indications of involvement from local hackers. The breach, which was first disclosed by Odido on February 12, affected a staggering 6.2 million customers and exposed sensitive personal information.
According to the Dutch National Police (Politie), the investigation has uncovered evidence suggesting that Dutch-speaking individuals posed as Odido’s IT employees in a phishing scam. This ruse allowed them to gain access to the customer contact system on February 7, where they downloaded large amounts of user data. The police have described this type of investigation as complex and time-consuming, but also acknowledged that cybercriminals often leave behind digital footprints.
Odido, one of the largest telecommunications companies in the Netherlands, offers mobile, broadband, and television services to millions of customers across the country. In the aftermath of the breach, the company revealed that the attackers had accessed a range of sensitive information, including full names, addresses, phone numbers, email addresses, bank account details, and identification documents.
Interestingly, this investigation has also shed light on the activities of the notorious ShinyHunters extortion gang. While Odido has yet to attribute the breach directly to them, ShinyHunters claimed responsibility for the attack on their dark web leak site, releasing an 88GB archive containing over 15 million records. The gang has been linked to numerous high-profile breaches in recent months, including attacks targeting Okta, Microsoft, and Google single sign-on (SSO) accounts.
The Dutch police’s investigation into the Odido breach is a timely reminder that cybersecurity threats can come from anywhere – even from within one’s own country. It highlights the importance of robust security measures and ongoing vigilance in detecting and preventing such attacks. As the ShinyHunters gang continues to wreak havoc on organizations worldwide, it’s crucial for companies to stay one step ahead of these threat actors.
In practical terms, this means that security teams should remain vigilant and not underestimate the sophistication of cybercriminals. With the right tools and strategies in place, it’s possible to detect and prevent many attacks before they even occur. As a final takeaway, consider implementing regular breach and attack simulation tests to ensure your SIEM and EDR rules are effective in detecting threats that might otherwise go unnoticed.
Source: Bleeping Computer — 2026-07-10