Skip to content
Dutch Police Investigate Local Suspects in Major Odido Data Breach

Dutch Police Investigate Local Suspects in Major Odido Data Breach

First seen 10 Jul 2026, 19:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •Odido breach exposed data of approximately 6.5 million customers.
  • •Attackers used voice phishing to bypass multi-factor authentication.
  • •Dutch police suspect local hackers and are seeking public assistance.

In February 2026, Odido, a major Dutch telecom provider, suffered a significant data breach affecting approximately 6.5 million customers. The breach was facilitated through a voice phishing (vishing) attack, where attackers impersonated IT staff to gain access to the company's Salesforce CRM system. Dutch police have identified strong indications that local criminals were involved, particularly a Dutch-speaking individual who misled customer service representatives. The breach exposed sensitive customer data, including names, addresses, and bank account details. The cybercriminal group ShinyHunters has claimed responsibility for the attack, which has prompted ongoing investigations by the Dutch National Police and the High Tech Crime Team. Authorities are urging the public to provide any information that could assist in identifying the suspects. The investigation remains active, with police considering releasing a voice recording of the suspect to aid in identification.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-02-05
Data breach occurred
Attackers accessed Odido's Salesforce CRM system, leading to the theft of customer data.
Techtimes
2026-02-12
Breach disclosed publicly
Odido confirmed the data breach affecting over 6 million customers, revealing the extent of the data exposure.
Bleepingcomputer
2026-07-09
Police announce investigation findings
Dutch police revealed strong indications of local involvement in the Odido breach, urging public assistance.
Cybernews

More articles in this cluster (14)

Common questions

What data was exposed in the breach?
The breach exposed names, addresses, phone numbers, bank account details, and identification numbers of approximately 6.5 million customers.
Who is responsible for the attack?
The cybercriminal group ShinyHunters has claimed responsibility for the attack, which involved local Dutch suspects.
What steps is Odido taking in response?
Odido is enhancing its cybersecurity measures and has committed to improving data protection practices following the breach.