A notorious cybercriminal group, ShinyHunters, has claimed responsibility for a massive data breach involving Odido and BEN, exposing millions of customer records.
The group asserts that Odido, a Dutch telecommunications provider, was not truthful in its initial disclosure of the incident.
This development suggests the breach may be significantly larger and more severe than initially reported.
ShinyHunters is known for high-profile data theft and extortion campaigns. In this instance, the group claims to have stolen a vast amount of sensitive information.
If the allegations are accurate, the incident represents a substantial security failure with severe implications for the affected individuals and the company.
According to International Cyber Digest, the group’s statement regarding Odido’s transparency adds a layer of complexity to the ongoing investigation.
Exposed Customer Information
The compromised data reportedly includes 21 million records belonging to approximately 8 million customers.
The nature of the stolen information is highly sensitive and poses a significant risk for identity theft and financial fraud. The sheer volume of records indicates a widespread compromise of Odido’s systems.
The stolen information allegedly includes:
- Plaintext passwords
- Passport and driver’s license numbers
- International Bank Account Numbers (IBANs)
- Physical addresses
- Email addresses
- Internal company documents
- Source code
The inclusion of plaintext passwords is particularly alarming, as it allows attackers immediate access to user accounts.
Passport numbers and IBANs can be exploited for severe financial crimes. The theft of internal documents and source code also poses a significant risk to Odido’s operational security and intellectual property.
Implications and Response
The potential fallout from this breach is extensive. Customers whose data has been exposed are at high risk for phishing attacks, credential stuffing, and identity theft.
The exposure of financial and personal identification details requires immediate action from affected individuals to secure their accounts and monitor for suspicious activity.
Odido faces significant regulatory and reputational challenges in the wake of these allegations.
The company must conduct a thorough investigation to determine the full extent of the breach and notify affected customers appropriately.
Regulatory bodies will likely scrutinize Odido’s security practices and its handling of the incident disclosure.
The situation underscores the critical need for robust cybersecurity measures and transparent communication during data breach events.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





