Bleepingcomputer Dutch Police Investigate Local Suspects in Major Odido Data Breach
Article Content
- •Odido breach exposed data of approximately 6.5 million customers.
- •Attackers used voice phishing to bypass multi-factor authentication.
- •Dutch police suspect local hackers and are seeking public assistance.
In February 2026, Odido, a major Dutch telecom provider, suffered a significant data breach affecting approximately 6.5 million customers. The breach was facilitated through a voice phishing (vishing) attack, where attackers impersonated IT staff to gain access to the company's Salesforce CRM system. Dutch police have identified strong indications that local criminals were involved, particularly a Dutch-speaking individual who misled customer service representatives. The breach exposed sensitive customer data, including names, addresses, and bank account details. The cybercriminal group ShinyHunters has claimed responsibility for the attack, which has prompted ongoing investigations by the Dutch National Police and the High Tech Crime Team. Authorities are urging the public to provide any information that could assist in identifying the suspects. The investigation remains active, with police considering releasing a voice recording of the suspect to aid in identification.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Common questions
What data was exposed in the breach?
Who is responsible for the attack?
What steps is Odido taking in response?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…