A Dutch Telecom Firm’s Data Breach May Be Linked to Local Hackers
In a significant development, the Dutch National Police has revealed “strong indications” that local hackers were involved in a major data breach at Odido, one of the country’s largest telecommunications providers. The company disclosed the attack on February 12, stating that the attackers accessed its customer contact system and downloaded personal data from millions of users.
The investigation suggests that Dutch-speaking hackers posed as IT employees to gain access to Odido’s systems through phishing attacks. A telephone conversation with a customer service representative shortly before the breach is believed to have played a key role in the attack. The police emphasized that their investigation, which is still ongoing, has uncovered evidence and “traces” left behind by the cybercriminals.
The Odido data breach affected approximately 6.2 million customers, exposing sensitive information such as names, addresses, phone numbers, email addresses, bank account details, and identification documents like passports or driver’s licenses. While no call records or billing data were compromised, the breach has raised concerns about the potential for identity theft and financial fraud.
The ShinyHunters extortion gang claimed responsibility for the breach on its dark web leak site, releasing a massive 88GB archive containing over 15 million records. This group is notorious for targeting companies with widespread vishing campaigns, impersonating IT support staff to trick employees into entering credentials and multi-factor authentication codes on phishing sites.
ShinyHunters has been linked to numerous high-profile breaches in recent years, including attacks on Okta, Microsoft, Google, and various other organizations. The group’s modus operandi involves breaching corporate single sign-on (SSO) accounts, stealing data from connected SaaS applications like Microsoft 365 and Salesforce.
The Odido breach is a stark reminder of the need for robust cybersecurity measures in the face of increasingly sophisticated attacks. While law enforcement efforts can help track down cybercriminals, it’s essential for organizations to prioritize security awareness training, implement multi-layered defenses, and regularly test their systems for vulnerabilities.
For individuals affected by the breach, it’s crucial to remain vigilant and monitor their financial accounts closely. Staying informed about potential threats and taking proactive steps to protect personal data can help mitigate the risks associated with such breaches.
Source: Bleeping Computer — 2026-07-10