Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS
September 8, 2026
US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
September 8, 2026
Best Managed XDR Services for 2026
September 8, 2026
Home/CyberSecurity News/ShinyHunters Breaches Ticketmaster, Exposing 560 Million Customer Records
CyberSecurity News

ShinyHunters Breaches Ticketmaster, Exposing 560 Million Customer Records

Key Takeaways Dutch telecom giant Odido suffered a significant data breach affecting approximately 6.39 million customers. The breach was initiated by the ShinyHunters hacking group through a social...

Emy Elsamnoudy
Emy Elsamnoudy
September 8, 2026 5 Min Read
4 0

Key Takeaways

  • Dutch telecom giant Odido suffered a significant data breach affecting approximately 6.39 million customers.
  • The breach was initiated by the ShinyHunters hacking group through a social engineering phone call to Odido’s customer service, bypassing multi-factor authentication.
  • Sensitive customer data, including names, addresses, phone numbers, and IBANs, was exfiltrated from Odido’s Salesforce CRM system.
  • Dutch police have publicly released the voice of the suspected caller in an effort to identify him.

A sophisticated social engineering attack, originating from a single phone call, has led to one of the most extensive data breaches in Dutch history, impacting Dutch telecom provider Odido and its subsidiary Ben. The notorious hacking collective ShinyHunters, known for exploiting human vulnerabilities rather than complex technical exploits, orchestrated the compromise of over six million customer records.

Table Of Content

  • Key Takeaways
  • The Social Engineering Playbook
  • Massive Data Exfiltration
  • The Ongoing Investigation and Public Appeal
  • What You Should Do

Dutch law enforcement has taken the unusual step of releasing the voice of the suspected perpetrator to the public, hoping to identify the individual responsible for initiating the breach.

The Social Engineering Playbook

Investigators detail that on February 5 and 6, a Dutch-speaking individual contacted Odido’s customer service helpdesk. The caller reportedly used specific English IT terminology and convincingly impersonated an internal IT department colleague. This individual claimed an urgent technical issue required immediate attention.

An unsuspecting Odido employee, believing the caller to be legitimate, granted access to what appeared to be an internal system. In reality, this was a carefully crafted credential-harvesting setup deployed by the attackers. During this interaction, the caller successfully captured a username, password, and even a multi-factor authentication (MFA) token, effectively neutralizing a critical security layer for Odido.

With the stolen credentials, the attackers gained unauthorized entry into Odido’s Salesforce-based Customer Relationship Management (CRM) environment, the very system used to manage customer interactions and data.

Massive Data Exfiltration

Approximately two days later, a substantial 90 GB of data, comprising around 15 million rows, was covertly exfiltrated. This data transfer occurred through legitimate Salesforce APIs, allowing the activity to blend with normal network traffic and avoid immediate detection.

Odido has since confirmed that unauthorized access to its customer contact system took place on February 7 and 8, and that the intrusion was promptly contained upon discovery.

Odido’s official update places the final count of affected individuals at approximately 6.39 million, covering both active and inactive customers of Odido and Ben. Earlier estimates from company representatives and media reports had varied between 6.1 million and 6.2 million. ShinyHunters, however, boasted of exfiltrating nearly 21 million records, a figure likely inflated by duplicate entries and internal corporate metadata alongside genuine customer profiles.

The compromised dataset included highly sensitive personal information such as full names, home addresses, phone numbers, email addresses, dates of birth, customer numbers, IBAN bank account details, and identification document numbers like passports and driver’s licenses.

While Odido maintains that no account passwords, call records, or billing data were compromised, ShinyHunters publicly disputed this, claiming plaintext passwords and internal corporate files were also part of the stolen haul. The “Have I Been Pwned” service later validated that approximately 6 million unique email addresses from the breach were subsequently published across four separate data releases.

ShinyHunters reportedly demanded a ransom of approximately one million euros to prevent the publication of the stolen data. Odido refused to pay, a decision the company publicly defended. In response, the group began releasing the data in stages from February 26, culminating in the complete publication of the cache by March 1.

The repercussions were immediate. Cybersecurity researchers monitoring two email aliases known only to Odido and rival carrier Tele2 observed 61 phishing emails within 150 days of the data going public, illustrating the rapid weaponization of leaked personal data for subsequent fraud and vishing campaigns.

The Dutch police also incorporated affected customers’ email addresses into their “Check je hack” tool, enabling individuals to verify if their information was part of the compromised dataset.

The Ongoing Investigation and Public Appeal

The investigation, spearheaded by the Landelijk Parket and executed by the High Tech Crime Team within the National Police’s Unit for National Investigation and Interventions, has been active since shortly after the breach was disclosed.

In July 2026, investigators announced “strong indications” of Dutch national involvement, specifically focusing on the pivotal phone call preceding the hack. Police publicly urged the caller to come forward voluntarily, warning that his voice might otherwise be released.

Following a lack of response to this appeal, Dutch police broadcast the full recording on the true-crime program Opsporing Verzocht on Monday, September 7, at 21:15 on NPO2.

A voice expert consulted by investigators confirmed the recording as a genuine human voice, not AI-generated. The expert described the caller as speaking Dutch with clear ICT knowledge, deliberate use of English technical jargon, and a distinctive verbal tic: the Dutch filler word “hoor”. Authorities are now soliciting tips from the public via politie.nl/odido, the anonymous tip line Meld Misdaad Anoniem, or the Telegram channel @Veiligmelden.

Security analysts have identified three critical systemic vulnerabilities that allowed a single phone call to escalate into a breach of this magnitude: the absence of callback verification or out-of-band checks at the helpdesk, overly permissive access that enabled a single compromised account to bulk-export an entire customer database, and insufficient monitoring to flag a 90 GB data transfer as anomalous.

ShinyHunters has historically employed nearly identical phone-based social engineering tactics against over 100 organizations globally, including prominent entities like SoundCloud, Crunchbase, and Betterment, often bypassing single sign-on protections without requiring a technical exploit.

What You Should Do

  • Monitor for Phishing Attempts: Be extremely vigilant for suspicious emails, texts, or calls that claim to be from Odido or other service providers. Attackers often leverage stolen data for highly targeted phishing (spear-phishing) and vishing campaigns.
  • Check Your Email Address: Utilize services like “Have I Been Pwned” or the Dutch police’s “Check je hack” tool to determine if your email address was part of the compromised dataset.
  • Enable Multi-Factor Authentication (MFA): Ensure MFA is enabled on all your online accounts, especially for financial services and critical platforms. While MFA was bypassed in this incident, it remains a crucial security layer against many other types of credential theft.
  • Beware of Impersonation: Be skeptical of unsolicited calls or emails requesting sensitive information or asking you to grant remote access. Always verify the caller’s identity through an official, independently verified contact number.
  • Review Bank Statements: Closely monitor your bank accounts and financial statements for any unauthorized activity, given that IBAN details were exposed.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityExploitphishingSecurity

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

InjectEave Attack Recovers Audio from Headphones Up to 30 Meters Away

Next Post

Shai-Hulud npm Worm Evades Scanners, Resurfaces After 111 Days

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaw in HashiCorp Terraform Registry Lets Attackers Steal Cloud Credentials
September 8, 2026
Top 10 Web Application Firewall Solutions for 2026
September 8, 2026
Top Firewall-as-a-Service (FWaaS) Providers in 2026
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us