2026 ShinyHunters breach — 6.5M individuals, 600K companies
Data compromised
Names, addresses, phones, emails, bank accounts (IBAN), DOB, passports, driver's licenses, BSN, customer service notes
Technical writeup
ShinyHunters breached Dutch telecom Odido (formerly T-Mobile NL) Feb 7-8, 2026 via AI voice phishing targeting CRM. 6.5M individuals and ~600K companies affected. After Odido refused €1M ransom (reduced to €500K), hackers released data daily from Feb 27; full cache published March 1. Exposed: 5M+ ID documents (passports, driver's licenses), bank accounts, DOB, addresses, customer service notes. Identity fraud cases more than doubled. July 10, 2026 update: Dutch National Police (Politie) said investigation found strong indications Dutch-speaking attackers posed as Odido IT staff in a customer-service call shortly before the February 7 phishing-led theft; traces were secured during the ongoing probe per BleepingComputer reporting on a July 8 Politie release.
Root cause
AI voice phishing; CRM compromise; ShinyHunters
References
- https://www.bleepingcomputer.com/news/security/police-suspects-dutch-hackers-were-involved-in-odido-breach/
- https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html
- https://nltimes.nl/2026/02/12/odido-cyber-attack-hackers-gained-access-62-million-peoples-data
- https://nltimes.nl/2026/03/01/hackers-publish-full-cache-stolen-odido-customer-data-ransom-refusal
- https://www.theregister.com/2026/02/27/odido_shinyhunters_leaks/
- https://en.wikipedia.org/wiki/List_of_data_breaches