ShinyHunters' Phone Call Breach Exposes 6 Million Customer Records
In a shocking data breach, Dutch telecom giant Odido and its budget subsidiary Ben fell victim to ShinyHunters, a notorious hacking collective. A single phone call on February 5, 2026, was all it took for the attackers to gain access to the customer service helpdesk, where they convinced an employee to grant them access to internal systems.
The caller, who spoke Dutch with demonstrable ICT knowledge and used English technical jargon, captured a username, password, and multi-factor authentication token during the interaction. With these credentials in hand, the attackers pivoted into Odido's Salesforce-based customer relationship management environment and exfiltrated 90 GB of data, including personal records of over six million customers.
The breach exposed sensitive information such as full names, home addresses, phone numbers, email addresses, dates of birth, customer numbers, IBAN bank account details, and identification document numbers. ShinyHunters reportedly demanded a ransom of around one million euros to prevent publication of the stolen dataset, but Odido refused to pay.
The attackers released the data in stages starting February 26, ultimately publishing the complete cache by March 1. The fallout was immediate, with cybersecurity researchers tracking 61 phishing emails arriving within 150 days of the leak going public.