ShinyHunters Gained Access to 6 Million Customers’ Records Using a Single Call

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A single phone call was all it took to trigger one of the largest data breaches in Dutch history. In early February 2026, Dutch telecom giant Odido and its budget subsidiary Ben became the latest casualties of ShinyHunters, a hacking and extortion collective notorious for using social engineering rather than sophisticated exploits to breach corporate defenses.

The attack exposed the personal records of more than six million customers, and Dutch police have now gone public with the suspected caller’s actual voice in a bid to identify him.

According to investigators, a Dutch-speaking man contacted Odido’s customer service helpdesk on February 5 and 6, using specific English-language IT jargon and confidently impersonating a colleague from the IT department.

He told the employee a problem urgently needed fixing, and the unsuspecting worker granted him access to what appeared to be a legitimate internal system but was, in reality, a credential-harvesting setup engineered by the attackers. Within that single interaction, the caller captured a username, password, and even a multi-factor authentication token, effectively neutralizing one of Odido’s key security layers.

With those stolen credentials in hand, the attackers pivoted into Odido’s Salesforce-based customer relationship management (CRM) environment, the same system used to log and manage customer interactions.

Massive Data Breach

Two days later, roughly 90 GB of data spanning about 15 million rows was quietly exfiltrated through legitimate Salesforce APIs, meaning the exporting activity blended in with normal, authorized traffic rather than triggering obvious alarms.

Odido has since confirmed that unauthorized access to its customer contact system occurred on February 7 and 8, and that the intrusion was shut down as soon as it was detected.

Odido’s official update places the final number of affected individuals at approximately 6.39 million, encompassing both active and inactive customers of Odido and Ben. Earlier estimates from company representatives and media reports ranged between 6.1 million and 6.2 million people, while ShinyHunters itself claimed to have exfiltrated close to 21 million records, a figure that likely includes duplicate entries and internal corporate metadata alongside customer profiles.

The stolen dataset reportedly included full names, home addresses, phone numbers, email addresses, dates of birth, customer numbers, IBAN bank account details, and identification document numbers such as passports and driver’s licenses.

Odido has maintained that no account passwords, call records, or billing data were compromised, though ShinyHunters disputed this, claiming plaintext passwords and internal corporate files were also part of the haul. Have I Been Pwned later confirmed roughly 6 million unique email addresses were published across four separate data releases.

ShinyHunters reportedly demanded a ransom of around one million euros to prevent publication of the stolen dataset. Odido refused to pay, a decision the company later defended publicly, and the group responded by releasing the data in stages starting February 26, ultimately publishing the complete cache by March 1.

The fallout was immediate. Cybersecurity researchers tracking two email aliases known only to Odido and rival carrier Tele2 recorded 61 phishing emails arriving within 150 days of the leak going public, underscoring how quickly leaked personal data gets weaponized for follow-on fraud and vishing campaigns.

Dutch police also added affected customers’ email addresses to their “Check je hack” tool, allowing individuals to verify whether their information was part of the stolen dataset.

The investigation, led by the Landelijk Parket and carried out by the High Tech Crime Team within the National Police’s Unit for National Investigation and Interventions, has been running since shortly after the breach was disclosed.

In July 2026, investigators announced they had found “strong indications” that Dutch nationals were involved, centering on the phone call placed just before the hack. Police publicly urged the caller to come forward voluntarily, warning that his voice could otherwise be released.

When no one responded to that appeal, Dutch police aired the full recording on the true-crime program Opsporing Verzocht on Monday, September 7, at 21:15 on NPO2.

A voice expert consulted by investigators concluded the recording is a genuine human voice rather than an AI-generated one, and described the caller as speaking Dutch with demonstrable ICT knowledge, deliberate use of English technical jargon, and a distinctive verbal tic, the Dutch filler word “hoor”. Authorities are now asking the public to submit tips through politie.nl/odido, the anonymous tip line Meld Misdaad Anoniem, or the Telegram channel @Veiligmelden.

Security analysts have pointed to three systemic failures that allowed a single phone call to cascade into a breach of this magnitude: the absence of callback verification or out-of-band checks at the helpdesk, overly permissive access that let one compromised account bulk-export an entire customer database, and inadequate monitoring capable of flagging a 90 GB data transfer as anomalous.

ShinyHunters has used nearly identical phone-based social engineering tactics against more than 100 organizations worldwide, including SoundCloud, Crunchbase, and Betterment, often bypassing single sign-on protections entirely without needing a technical exploit.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post ShinyHunters Gained Access to 6 Million Customers’ Records Using a Single Call appeared first on Cyber Security News.