Dutch Telecoms Suffer Major Breach From Single Mis‑dial, Leaking Data of Six Million Users
One misplaced phone call triggered one of the largest data breaches ever recorded in the Netherlands, allowing the hacking collective ShinyHunters to obtain personal data belonging to about six million subscribers of the telecom provider Odido and its budget brand Ben.
Investigators say the perpetrators used an ordinary support hotline, impersonated a genuine staff member and persuaded a call‑center operator to provide remote entry to internal systems. After gaining entry, they harvested subscriber data—including names, addresses, phone numbers and billing information—and warned they would release the files unless a ransom was paid.
ShinyHunters, a group that has appeared in several high‑profile extortion operations throughout Europe, is noted for relying on social engineering instead of advanced malware. By manipulating human trust, the gang can sidestep technical defenses with little effort, a method that proved pivotal in this case.
Revealed in early February 2026, the breach impacts both Odido’s primary network and Ben, its low‑cost offshoot that caters to many price‑conscious customers. Although the firm has not verified the precise extent of the exposed data, regulatory documents indicate the records could facilitate identity theft or bogus billing.
A spokesperson for Odido said the compromised entry point was shut down at once, a thorough forensic investigation launched, and extra authentication safeguards introduced for employees. The company also started informing the impacted customers and provided a year of complimentary credit‑monitoring.
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has initiated a formal probe, pointing to possible breaches of the EU General Data Protection Regulation (GDPR). Depending on the outcome, Odido may be liable for penalties reaching 4% of its worldwide revenue, together with required corrective actions.
Consumer‑advocacy organisations are advising individuals to watch their account activity, update passwords and stay alert to unexpected messages that mention the breach. As the inquiry continues, analysts note the episode highlights the necessity for telecom firms to strengthen both technical safeguards and employee training against social‑engineering attacks.
Comments (0)
Be the first to comment.
Join the discussion