← Odido

2026 ShinyHunters breach — 6.5M individuals, 600K companies

2026 6.5M records affected Share on X

Data compromised

Names, addresses, phones, emails, bank accounts (IBAN), DOB, passports, driver's licenses, BSN, customer service notes

Technical writeup

ShinyHunters breached Dutch telecom Odido (formerly T-Mobile NL) Feb 7-8, 2026 via AI voice phishing targeting CRM. 6.5M individuals and ~600K companies affected. After Odido refused €1M ransom (reduced to €500K), hackers released data daily from Feb 27; full cache published March 1. Exposed: 5M+ ID documents (passports, driver's licenses), bank accounts, DOB, addresses, customer service notes. Identity fraud cases more than doubled. July 10, 2026 update: Dutch National Police (Politie) said investigation found strong indications Dutch-speaking attackers posed as Odido IT staff in a customer-service call shortly before the February 7 phishing-led theft; traces were secured during the ongoing probe per BleepingComputer reporting on a July 8 Politie release.

Root cause

AI voice phishing; CRM compromise; ShinyHunters

References