Cybercriminal group ShinyHunters reportedly accessed the personal information of approximately 6.39 million current and former Odido and Ben customers after using a voice-phishing attack to compromise employee accounts.

 

What happened

According to Cyber Security News, a sophisticated voice-phishing campaign allowed the cybercriminal group ShinyHunters to gain access to customer service accounts at Dutch telecommunications provider Odido and access millions of customer records.The incident affected approximately 6.39 million people, including current and former Odido and Ben customers, according to Odido.

After obtaining the data, ShinyHunters demanded a ransom from Odido in exchange for not publishing the stolen information. Odido refused to pay, and the attackers subsequently threatened to release the data publicly.

 

Going deeper

ShinyHunters targeted Odido in early February 2026 using a combination of phishing and voice-based social engineering, also known as vishing. According to Odido, the attacker contacted its customer service team while pretending to be a member of the company's IT department. The first vishing attack occurred on February 5, followed by another attack on February 6.

Dutch broadcaster NOS reported that the attackers first obtained the passwords of individual customer service employees through phishing. They then called the employees and posed as Odido's IT department, persuading them to approve a fraudulent login attempt and bypass an additional security step. Multiple employee accounts were reportedly compromised.

The attackers subsequently gained access to Odido's customer contact system, where they were able to access a large volume of customer information.

Odido initially reported that approximately 6.2 million accounts were affected. The company later updated the figure to approximately 6.39 million people after further analysis.

The compromised information included personal and contact information. Reporting on the incident has indicated that the exposed data included names, addresses, telephone numbers, email addresses, dates of birth, and customer numbers, as well as financial and identity-related information in some records.

Odido said its telecommunications services were not disrupted and that customers could continue to use its network, internet, and other services normally.

 

What was said

In an update posted on the website, Odido CEO Søren Abildgaard acknowledged the impact of the attack and said the company understood the concerns raised by affected customers. “I deeply regret that this happened and recognize the concern and uncertainty that this incident has caused for those affected,” Abildgaard said. He added that while Odido could not change what had already happened, it could determine how it protects customers in the future. Abildgaard said the company would continue strengthening its cybersecurity capabilities in response to increasingly sophisticated threats. “We promise to continue investing in our organizational capabilities to ensure our defenses stay up-to-date with the increased sophistication of cyber threats,” he said.

The CEO also addressed Odido’s decision not to pay the ransom demanded by the attackers. The company said it followed guidance from authorities and understood that refusing to pay could result in the stolen information being published. “We knew that this decision could lead to the stolen data being published,” Odido said. However, the company maintained that paying the ransom was not an option. “We strongly believe that criminal organizations should not be rewarded for illegal activities,” the company said, adding that paying could potentially put other Dutch businesses at risk.

Odido also acknowledged that communicating the full impact of the breach was challenging. The company initially notified millions of customers after confirming that their data had been affected, while further analysis later identified additional customers who needed to be contacted. “One of the most important lessons we’ve learned is how difficult it can be for an organization – particularly one of our size – to complete a full analysis of the data impacted in a cyberattack,” Odido said.

Looking ahead, Odido said it is working with external cybersecurity experts, has introduced additional security measures, and has established a task force to assess its IT environment. It is also introducing additional cybersecurity training for employees and reviewing its data retention practices. “We will learn from this experience,” Abildgaard said. He added that Odido would “communicate openly with customers” and share its lessons to help protect against emerging cyber threats.

Abildgaard acknowledged that the company still has work to do to rebuild customer confidence, stating: “I know that there is more to do to address your concerns, improve as an organization, and earn back your trust,” he said.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

The bigger picture

The Odido breach adds a major Dutch telecommunications company to ShinyHunters’ growing list of victims, highlighting how the group’s increasingly sophisticated tactics are being used against organizations beyond the US.

ShinyHunters emerged publicly around 2020 and has developed a reputation for large-scale data theft, credential theft, and “pay-or-leak” extortion campaigns. The group has also increasingly turned to cloud and software-as-a-service platforms, using social engineering and voice phishing to compromise employee accounts. Its previous high-profile victims include Ticketmaster, Santander, and AT&T, with attacks exposing data belonging to millions of people. The group has targeted organizations across industries, including healthcare, banking, retail, technology, and telecommunications.

The attack on Odido shows that this threat is not confined to American companies. By using voice phishing to impersonate IT personnel, ShinyHunters was reportedly able to compromise employee accounts at a major Dutch telecommunications provider and gain access to information belonging to approximately 6.39 million people.

The incident demonstrates the increasingly international nature of cybercrime. ShinyHunters' established reputation and attack methods can be replicated across borders, allowing the group to target organizations wherever employees, cloud platforms, and customer databases provide opportunities for access.

Learn more: Who are the ShinyHunters?

 

FAQS

What is voice phishing?

Voice phishing, or vishing, is a type of social engineering attack in which criminals use phone calls to trick victims into revealing information, approving authentication requests or performing actions that give attackers access to systems.

 

What happens to data after a ransomware or extortion attack?

Attackers may threaten to publish or sell stolen information if an organisation refuses to pay. They may also use the data for additional fraud, phishing or extortion attempts.

 

How do organisations detect data breaches?

Organisations may identify breaches through security monitoring, unusual account activity, alerts from cybersecurity systems, employee reports or investigations following suspicious activity.

 

Should organisations pay a ransom after a cyberattack?

There is no universal answer. Organisations must consider legal, regulatory, operational and security implications, while recognising that payment does not guarantee that stolen data will be deleted or that attackers will not target them again.