Odido only learned of 6.2 million-record breach when hackers told it
How ShinyHunters stole data on 6.2 million Odido and Ben customers with one phone call, why no alarm went off, and what defenders can check.
Updated October 11, 2026
Dutch telecoms company Odido did not know that personal data on 6.2 million people had been stolen from its systems until the hackers told it, two days after the theft. "No alarm went off when the data was downloaded on Feb. 5," chief executive Tisha van Lammeren told Dutch broadcaster NOS on May 12, NL Times reported.
How the attackers got in
The attack started with a phone call. A member of the hacking group ShinyHunters called an Odido customer service employee, claimed to be from the company's IT department and talked the employee into logging in to a fake copy of the work environment. That gave the attacker the employee's login details, which were then used to download customer data on Feb. 5, 2026.
Odido blocked the compromised account within an hour. The same day, its own investigation and a review with an outside cybersecurity firm both concluded that no customer data had been taken. Both were wrong.
Two days later, a ransom demand
On Feb. 7, ShinyHunters contacted Odido and said it had the data. Odido disclosed the breach on Feb. 12. The stolen records included names, phone numbers, email addresses, bank account numbers and identity document details; Odido said no passwords, call records or billing information were involved. Customers of Odido and its Ben brand were affected.
The group demanded more than 1 million euros. Odido refused to pay, and in early March the group published the data of more than 6 million people on the dark web. Only then did Odido find out that records of business customers had been taken as well.
Van Lammeren called the publication of the data "a dark day for all of us." Asked about how the company kept customers informed, she said: "Looking back, I think we should have let something be known, also about things you don't know."
Two Dutch regulators are investigating whether Odido kept customer data secure and whether it held on to data for longer than it was allowed to. NL Times reported that it is not clear when those investigations will end.
What defenders can take from it
No software flaw was needed. One convincing phone call and a fake login page produced a valid account, and a valid account downloading data looked like normal work, so nothing raised an alarm.
| Check | Why it matters here |
|---|---|
| Phishing-resistant sign-in (security keys or passkeys) for staff who can reach customer data | A password typed into a fake page would not have been enough (MITRE ATT&CK T1566.004, T1078) |
| Call back anyone who phones claiming to be IT, on a number you already know | The attack began with one such call |
| Alerts on unusually large downloads from customer systems, even by a valid account | No alarm went off on Feb. 5 |
| Delete customer data that is no longer needed | Regulators are asking whether Odido kept data too long |
Since this article was first published
In July, Dutch police said they had strong indications that Dutch criminals were involved. Shortly before the hack, a Dutch-speaking man posing as an IT employee called Odido's customer service; police asked him to come forward and warned that his voice could otherwise be made public. The High Tech Crime Team is investigating under the direction of the National Public Prosecution Service, and police have taken offline several servers the group used to spread the data, Security Affairs reported.
This article was updated on Oct. 11, 2026: the breach took place in February 2026, not 2024; Odido learned of it when the hackers contacted the company, not when they published the data, and the headline now says so. Police findings from July and sources were added.
Sources

Editor & Founder
Peter OlaleruPeter is the founder of Measured Take and a cybersecurity professional. He covers breaches, vulnerabilities, threat intelligence, APTs, and compliance. His reporting draws on hands-on experience in the security industry to make complex threats understandable.
More from Cybersecurity
Conversation
Reader notes
Loading comments...