Thursday, September 10, 2026

Odido Faces Alleged Data Breach as ShinyHunters Claims 21M Records Exposed

A notorious cybercriminal group, ShinyHunters, has claimed responsibility for a massive data breach involving Odido and BEN, exposing millions of customer records.

The group asserts that Odido, a Dutch telecommunications provider, was not truthful in its initial disclosure of the incident.

This development suggests the breach may be significantly larger and more severe than initially reported.

ShinyHunters is known for high-profile data theft and extortion campaigns. In this instance, the group claims to have stolen a vast amount of sensitive information.

If the allegations are accurate, the incident represents a substantial security failure with severe implications for the affected individuals and the company.

According to International Cyber Digest, the group’s statement regarding Odido’s transparency adds a layer of complexity to the ongoing investigation.

Exposed Customer Information

The compromised data reportedly includes 21 million records belonging to approximately 8 million customers.

The nature of the stolen information is highly sensitive and poses a significant risk for identity theft and financial fraud. The sheer volume of records indicates a widespread compromise of Odido’s systems.

The stolen information allegedly includes:

  • Plaintext passwords
  • Passport and driver’s license numbers
  • International Bank Account Numbers (IBANs)
  • Physical addresses
  • Email addresses
  • Internal company documents
  • Source code

The inclusion of plaintext passwords is particularly alarming, as it allows attackers immediate access to user accounts.

Passport numbers and IBANs can be exploited for severe financial crimes. The theft of internal documents and source code also poses a significant risk to Odido’s operational security and intellectual property.

Implications and Response

The potential fallout from this breach is extensive. Customers whose data has been exposed are at high risk for phishing attacks, credential stuffing, and identity theft.

The exposure of financial and personal identification details requires immediate action from affected individuals to secure their accounts and monitor for suspicious activity.

Odido faces significant regulatory and reputational challenges in the wake of these allegations.

The company must conduct a thorough investigation to determine the full extent of the breach and notify affected customers appropriately.

Regulatory bodies will likely scrutinize Odido’s security practices and its handling of the incident disclosure.

The situation underscores the critical need for robust cybersecurity measures and transparent communication during data breach events.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News