Introduction
In February 2026, Odido, one of the major Dutch telecommunications operators, was hit by a serious cybersecurity incident. A criminal group stole personal data belonging to millions of customers, then threatened to make it public unless a ransom was paid. The case has reignited the debate on personal data protection in the telecommunications sector.
What happened
Between February 7 and 8, 2026, unauthorized individuals gained access to an Odido customer contact system, managing to copy a large amount of personal data. Odido disclosed the breach on February 12, 2026, stating that approximately 6.2 million customers had been affected. The criminal group known as ShinyHunters, however, claimed to be in possession of 21 million records, corresponding according to them to 8 million customers. It is still unclear which of the two figures accurately reflects reality.
The stolen data includes highly sensitive information: full names, addresses, email addresses, phone numbers, IBAN numbers, passport numbers, driver’s license numbers, dates of birth, and customer numbers. This is a combination of information that, taken together, can be used to commit fraud or identity theft. It is important to note that Odido’s core infrastructure was not compromised: mobile phone, broadband internet, and television services continued to operate normally.
ShinyHunters set a deadline of February 26, 2026, demanding a ransom of over one million euros. With Odido’s response to the demand remaining unknown, the group began publishing the data starting February 27, 2026, releasing approximately 2 million records per day.
Why it matters and what the potential impact is
When data such as bank account numbers, identity documents, and complete personal information are stolen, the risk to the individuals involved is real and prolonged over time. Criminals can use this information to open fake accounts, apply for credit, impersonate victims, or carry out targeted scams. The danger does not end immediately: data published online remains accessible for a long time.
What companies and users can do
Anyone who believes they are an Odido customer should pay particular attention to unexpected communications, especially those requesting personal data or payments. It is advisable to monitor your bank accounts and, if necessary, contact your bank to report the situation. Companies, for their part, should assess the adequacy of their customer data access systems and review their incident response procedures.
Final takeaways
- The breach involved highly sensitive data belonging to millions of people, with real risks of fraud and identity theft.
- Odido’s operational infrastructure was not affected, but the stolen personal data can cause lasting harm to the individuals involved.
- In the event of incidents of this kind, it is essential that people remain vigilant and monitor suspicious activity related to their documents and accounts.
Sources:
https://cyberinsider.com/shinyhunters-claims-odido-breach-threatens-to-leak-21-million-records/
https://www.bleepingcomputer.com/news/security/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/
https://cybernews.com/security/shinyhunters-leak-odido-customer-records/
https://ioplus.nl/en/posts/odido-data-leak-looms-as-hacker-deadline-expires
Source: Security Affairs