Dutch investigators have identified a Dutch-speaking man as a likely participant in the February cyberattack on Odido, the Netherlands’ largest telecom — a breach that exposed the financial identities of 6.5 million people and is the largest personal data exposure in Dutch history. The Dutch National Police (Politie) announced Thursday that it has found “strong indications” that Dutch-speaking criminals were involved, that servers used to distribute the stolen data have been seized, and that a recording of the suspect’s voice could be released publicly if the investigation requires it.

The case has now been open for five months. No arrests have been announced, but investigators believe the perpetrators have discussed their involvement online or within their social circles — which is why police are now calling on anyone with information to come forward. The announcement marks the first time Dutch authorities have publicly characterized the suspect pool as domestic rather than a purely foreign-operated crime.

What made the breach possible was not a zero-day exploit or sophisticated malware. It was a phone call — and specifically, the kind of phone call that current enterprise security infrastructure is structurally poorly equipped to stop.

Phone Call That Bypassed MFA and Scraped Six Million Records

The attack began with standard phishing: the attackers sent emails to Odido customer service employees that captured their Salesforce CRM login credentials. But stolen credentials alone were not enough, because Odido’s system required multi-factor authentication. So the attackers called those same employees while posing as Odido’s own IT department, telling them they were updating MFA settings.

The callers directed employees to credential-harvesting websites that mimicked Odido and Salesforce login pages in real time — fake portals that could display the same MFA prompts the employees were accustomed to seeing. When employees entered their authentication codes, the attackers captured them before expiry and used them to authenticate into Odido’s actual Salesforce environment. The entire sequence required no cryptographic attack, no unpatched vulnerability, and no malicious code. It required a caller who sounded like an IT technician and a website that looked like a login screen.

Once inside the Salesforce customer relationship management system, attackers used automated scripts to bulk-download records. Odido’s monitoring infrastructure did not flag the mass data export. The theft took place on or around February 5, 2026, without triggering any alarm. It was not until February 7 that the attackers themselves contacted Odido to inform the company that they had the data — and only after that contact did Odido begin its investigation. An internal review conducted before ShinyHunters made contact had incorrectly concluded that nothing had been stolen. CEO Tisha van Lammeren acknowledged this in May 2026: “We were extremely surprised by the speed with which everything happened.”

Salesforce, the CRM platform provider, had previously warned about this specific attack vector before the breach occurred, according to reporting by Dutch public broadcaster NOS and documents cited in the consumer group lawsuit, in Salesforce’s January warning about vishing — a security advisory published by Mandiant, Google’s threat intelligence arm, just days before the Odido breach. That warning, now central to the civil litigation, suggests the breach was not simply an unforeseeable attack — it was an attack for which the precautions had been recommended and not implemented.

“This type of investigation is often complex and takes time, but cybercriminals are also vulnerable and leave traces,” said Stan Duijf, head of operations at the National Investigation and Interventions Unit. “Traces have been secured at several points during the investigation into the hack at Odido, which the research team has continued to work on.”

What Was Stolen — and Why It Cannot Be Reset

The breach exposed data that cannot be changed. Unlike passwords or account numbers, the information Odido stored — full names, home addresses, mobile numbers, email addresses, customer numbers, IBAN bank account numbers, dates of birth, BSN social security numbers, and passport or driver’s license numbers — constitutes a permanent identity profile. A password breach can be mitigated by resetting the password. A breach containing an individual’s BSN, date of birth, and passport number creates a risk that lasts for the life of the document and beyond.

Odido initially estimated 6.2 million affected individuals. Analysis by security firm UpGuard, after the attackers published the full dataset on March 1, 2026, placed the figure at over 6.5 million people and approximately 600,000 companies. ShinyHunters claimed access to data for as many as 8 million customers. Have I Been Pwned, which ingested the data across four consecutive daily releases in late February and early March, records 6 million unique email addresses in the dataset.

The stolen records included far more than the standard personal contact data Odido initially described. Researchers found sensitive internal customer service notes — free-text fields recording payment disputes, personal circumstances, and in some cases explicit instructions such as “do not disclose this customer’s address” because of stalking or domestic violence. Those notes gave criminals not just contact data but the context needed to craft convincing, targeted fraud. Security expert Sijmen Ruwhof confirmed that the full dataset was available for download from the open internet with a single click, no special software required, within days of publication.

By March 5, 2026, reporting by RTL and Follow the Money had identified data belonging to four Dutch cabinet ministers, a senior employee of a Dutch intelligence service, three individuals under government protection, and more than 16,000 employees at strategically critical Dutch companies including ASML, NXP, Philips, Damen, and Thales. “When personal data of ministers and protected persons leaks, it touches on national security interests,” Ruwhof said. “Even if only one home address is now on the internet, it remains a very serious physical security issue.”

ShinyHunters’ Playbook — and Why Telecoms Were Already Targets

The group that claimed responsibility, ShinyHunters, has become the most prolific extortion brand in enterprise cybercrime over the past two years. Its approach is distinct: rather than exploiting software vulnerabilities, it targets the humans who have privileged access to software, particularly IT help desk personnel and customer service staff who can reset credentials, enroll new authentication devices, and approve access requests. Google’s Threat Intelligence Group documented the technique, tracking the actors behind ShinyHunters-branded operations across multiple clusters (UNC6240, UNC6661, UNC6671) and reporting in January 2026 that these campaigns deployed victim-branded credential harvesting sites in real time during live phone calls, synchronizing the attacker’s spoken prompts with MFA requests as they appeared on screen.

The reason this technique defeats MFA is structural: authentication codes are time-limited, and the attackers capture and replay them before expiry while still on the call. Phishing-resistant MFA methods such as FIDO2 passkeys or Okta FastPass would have blocked this attack because they cryptographically bind authentication to the legitimate domain — a fake website cannot relay a FIDO2 credential regardless of how convincing the caller sounds. But Odido, like the majority of enterprise organizations, relied on time-based MFA codes that can be replayed.

Mandiant’s M-Trends 2026 report, compiled from more than 500,000 hours of frontline incident response work in 2025, ranked vishing as the second most common initial infection vector globally and the single most common vector in cloud environments. Email phishing fell from 14% to 6% of initial intrusions between 2024 and 2025 as attackers shifted toward voice-based techniques that human monitoring catches less reliably.

EclecticIQ documented an August 2025 recruitment post on a ShinyHunters Telegram channel explicitly soliciting insider access at enterprise organizations — including access to Okta, Microsoft SSO, Citrix VPN, and enterprise CRM platforms — in exchange for financial rewards. Odido, as the Netherlands’ largest mobile provider, was precisely the kind of target the group had been positioning to breach.

In January 2026 alone — less than two weeks before the Odido breach — ShinyHunters-affiliated actors targeted more than 100 organizations in an SSO vishing wave that publicly named Betterment, Crunchbase, and SoundCloud among victims. The Odido attack came weeks later using the same playbook.

Ransom Refused, Data on Dark Web, Fraud Already Active

Odido refused to negotiate. ShinyHunters had demanded more than €1 million and, when the deadline passed on February 26, began releasing approximately one million customer records per day. On March 1, 2026, the group published the complete 88-gigabyte archive containing more than 15 million records in a single release. Dutch police backed Odido’s decision: “After all, if they are paid, their business model remains viable,” Duijf said at the time.

The data’s weaponization followed quickly. The Central Identity Fraud Reporting Point reported that inquiries linked to Odido more than doubled in the weeks after the leak. A particularly well-targeted phishing campaign emerged impersonating CJIB, the Dutch government fines collection agency — targeting only people who had held Odido subscriptions, which confirmed the stolen data was being cross-referenced for fraud. The specificity of that campaign removed any remaining doubt: the data was not only available, it was already being actively used.

ShinyHunters subsequently announced in June 2026 that all stolen data the group has ever published would be made permanently available through a distributed network of torrent files and mirrors — effectively removing any possibility of forced takedown for any victim organization.

Legal Accountability Piling Up

Five months after the breach, Odido faces accountability on three parallel tracks.

The criminal investigation, conducted by the Politie’s High Tech Crime Team under the direction of the National Public Prosecutor’s Office, remains open and active. No arrests have been announced. Investigators are calling on anyone with information to contact police and say they are reserving the option to release the caller’s voice recording publicly if needed.

The consumer class-action, filed April 20, 2026 by Consumers United in Court (CUIC) — a non-profit co-founded by Dutch privacy organization Privacy First and European advocacy group noyb — is being litigated under the Dutch WAMCA collective action framework. CUIC argues that Odido stored customer data for up to a decade beyond its own stated two-year retention policy, that the volume and sensitivity of the exposed data demonstrates Salesforce access controls were not properly configured, and that the company was insufficiently transparent with customers after the breach. CUIC chair Eliëtte Vaal stated that Odido treated the security of customer data as “an afterthought in its business operations.” The claim seeks approximately €500 per victim — a figure that, applied to 6.2 million affected individuals, produces potential liability exceeding €3 billion, which would make it the largest GDPR compensation case in Dutch legal history.

Odido has maintained that customers are not automatically entitled to compensation in the event of a data breach. That position may be legally correct but is being actively contested. Legal experts quoted by Dutch news outlet AD acknowledged that the case is more complicated than CUIC’s public position suggests, because proving individual harm is a legal requirement under Dutch law — though those experts noted that CUIC is unlikely to have brought the case without first assessing its feasibility.

The regulatory investigation by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is also ongoing, with no completion timeline. Under GDPR Article 83, Odido could face fines of up to €20 million or 4% of global annual turnover if the authority determines its data minimization practices or security controls were inadequate. A separate investigation by the Netherlands Inspectorate for Digital Infrastructure is examining whether Odido’s security measures met the standards required for a company holding this volume of sensitive personal data.

Voice Recording Still Has Not Been Released

The most dramatic element of Thursday’s police announcement was what it withheld: Dutch investigators already possess a recording of the caller’s voice — the Dutch-speaking man who posed as an Odido IT technician and provided the social engineering element that initiated the breach — but have not yet released it. Authorities are treating that recording as an investigative asset.

The call for public information is a standard investigative tactic in cases where police have forensic evidence but have not yet identified a specific individual. The fact that investigators believe the perpetrators have discussed their involvement with people in their social circles — combined with the availability of a voice recording — suggests that the investigation is at the stage where an identification is possible but has not yet been made.

For anyone who was or is an Odido, Ben, T-Mobile Netherlands, or Tele2 customer within the past decade: your data is most likely in the breach. Check your status at Have I Been Pwned (haveibeenpwned.com) or the Dutch police’s Check Je Hack tool. Monitor bank accounts for small unauthorized direct debits, which attackers use to test IBAN access before larger transactions. Be alert to calls or emails from CJIB or other Dutch government agencies if you did not initiate the contact — that campaign is confirmed to have used Odido stolen data. Current and former Odido customers can register for CUIC’s class-action at cuic.eu at no upfront cost.

Frequently Asked QuestionsWas my data stolen in the Odido breach, and how do I check?

If you were a customer of Odido, Ben, T-Mobile Netherlands, or Tele2 within the last decade, your data was very likely included in the breach. Odido and Dutch police both confirmed that the breach extended to former customers whose data should have been deleted under Odido’s own two-year retention policy. You can check whether your email address appeared in the dataset at Have I Been Pwned (haveibeenpwned.com) or through the Dutch police’s Check Je Hack tool.

How did ShinyHunters defeat multi-factor authentication to get into Odido’s systems?

The attackers used a two-step technique: first, they sent phishing emails to Odido customer service employees to steal their login credentials. Then they called those same employees while posing as Odido’s IT department, directing them to fake login pages that mimicked Odido’s real authentication system in real time. When employees entered their MFA codes on the fake pages, the attackers captured those codes and used them before they expired. This technique — voice phishing, or vishing — defeats standard time-based MFA because it relies on a human actively cooperating, not on breaking cryptography. Phishing-resistant methods such as FIDO2 passkeys, which cryptographically bind authentication to the real login domain, would have blocked this attack even if the employees had been deceived.

What should I do now if I was an Odido customer?

Monitor your bank accounts for unauthorized direct debits — exposed IBAN numbers can be used to set up payments without your knowledge. Be skeptical of any call or email from CJIB or other Dutch government agencies that you did not initiate. A confirmed post-breach phishing campaign specifically targeted former Odido customers with fake CJIB communications, using the stolen data to make them convincing. You can join the CUIC class-action lawsuit at cuic.eu for free. If you believe your identity has been used fraudulently, report it to the Central Identity Fraud Reporting Point (CMI).

Why could Odido store my data for a decade if I left years ago?

Odido’s official data retention policy stated a two-year limit for former customer records. The breach revealed that the company had retained data for some former customers for up to a decade, in apparent violation of that policy and of GDPR’s data minimization principle, which requires companies to hold data only as long as necessary for the original purpose. This retention failure is central to the CUIC class-action lawsuit and to the Dutch Data Protection Authority’s separate investigation. It is also the reason the breach affected far more people than Odido’s active customer base would suggest.