Wire Observer.
Technology

Dutch Telecoms Hit by Massive Breach After One Mis‑dialed Call, Exposing Six Million Users

Dutch Telecoms Hit by Massive Breach After One Mis‑dialed Call, Exposing Six Million Users

A single telephone call set off one of the biggest data breaches in Dutch history, giving the cyber‑crime group ShinyHunters access to the personal records of roughly six million customers of telecom operator Odido and its low‑cost brand Ben.

According to investigators, the attackers leveraged a routine support line, posing as a legitimate employee and convincing a call‑center agent to grant remote access to internal databases. Once inside, the group extracted subscriber information spanning names, addresses, phone numbers and billing details, then threatened to publish the data unless a ransom was paid.

ShinyHunters, which has surfaced in multiple high‑profile extortion campaigns across Europe, is known for its reliance on social engineering rather than sophisticated malware. By exploiting human trust, the collective can bypass technical safeguards with minimal effort, a tactic that proved decisive in this incident.

The breach, disclosed in early February 2026, affects both Odido’s main network and Ben, its budget subsidiary that serves a large share of price‑sensitive consumers. While the company has not confirmed the exact scope of the compromised data, regulatory filings suggest that the information could enable identity theft or fraudulent billing.

Odido’s spokesperson announced an immediate shutdown of the compromised access point, a comprehensive forensic audit and the deployment of additional authentication measures for internal staff. The firm also began notifying affected customers and offered free credit‑monitoring services for a year.

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has opened a formal investigation, citing potential violations of the EU General Data Protection Regulation (GDPR). Depending on the findings, Odido could face fines of up to 4% of its global turnover, as well as mandatory remediation steps.

Consumer‑advocacy groups are urging users to monitor account activity, change passwords and be wary of unsolicited communications that reference the breach. As the investigation proceeds, analysts say the incident underscores the need for telecom operators to reinforce not only technical defenses but also staff training against social‑engineering attacks.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related