News: 1772200452

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cops back Dutch telco Odido after second wave of ShinyHunters leaks

(2026/02/27)


The Netherlands' national police is backing Odido's refusal to pay a ransom after ShinyHunters leaked a second round of records belonging to the telco.

In the early hours of Friday morning, the cybercriminals behind ShinyHunters leaked 1 million Odido records for the second day in a row.

According to [1]Have I Been Pwned , which is ingesting the data from each day's leaks, the first million contained 317,000 unique email addresses, while the second round consisted of 371,000.

[2]

Details associated with those accounts include bank account numbers, other basic personal information, passport numbers, driving licenses, and customer service comments.

[3]

[4]

ShinyHunters' website indicates that it is once again gearing up for a third round of leaks on February 28. If this round is of a similar scale, it would push the total number of affected accounts past 1 million.

After the third round, the cybercrime group promised to begin leaking 2 million records a day. It claims to have stolen around 21 million in total.

[5]

Odido first confirmed the scale of the data leak weeks ago, saying [6]6.2 million customers were affected by the attack. The company's website is currently not reachable at the time of writing, although the website for subsidiary Ben, whose customers were also caught up in the data theft, is still working.

The telco has also confirmed that it will not be paying a ransom, an unknown sum that [7]ShinyHunters is demanding to stop the flow of leaked information into the public domain.

The Netherlands' national police (Politie) has reissued an alert advising organizations in similar positions to avoid paying ransoms, just like Odido.

[8]

"Our advice to ransomware victims is: don't pay if criminals demand a ransom," said Stan Duijf, head of operations responsible for combating cybercrime at the Politie. "After all, if they are paid, their business model remains viable.

[9]Wynn Resorts takes attacker's word for it that stolen staff data was deleted

[10]ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data

[11]Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant

[12]ShinyHunters claims it drove off with 1.7M CarGurus records

"The ultimate decision is up to the victim, but you can't assume your data is safe if you pay. We know from [13]research that criminals don't always delete the data , and may resell it or demand more money. If companies are hacked, it's crucial that they contact the police as soon as possible, so that together we can limit the damage and secure the evidence."

The Politie said Odido was fully complying with its investigation into the attack, and agreed with the company's advice to remain vigilant to potential targeted [14]phishing attacks , given the volume of data stolen.

The Register requested more information from Odido.

The last public statement made by the telco, penned by Søren Abildgaard, CEO at Odido Netherlands, and updated on February 26, said: "Our focus has always been on our customers, and that will remain so.

"On the advice of leading cybersecurity advisors and relevant government agencies, such as the police, Odido has decided not to negotiate with these criminals or allow themselves to be blackmailed by them.

"We remain committed to supporting and protecting our customers and employees in the best possible way."

Customers are being offered a 24-month subscription to F-Secure's digital security package, which provides protection for devices against malware, phishing, and other threats. ®

Get our [15]Tech Resources



[1] https://haveibeenpwned.com/Breach/Odido

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aaHNsxk8N3exCOs62g8GAAAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aaHNsxk8N3exCOs62g8GAAAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aaHNsxk8N3exCOs62g8GAAAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aaHNsxk8N3exCOs62g8GAAAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2026/02/13/odido_breach/

[7] https://www.theregister.com/2026/02/25/wynn_resorts_shinyhunters/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aaHNsxk8N3exCOs62g8GAAAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2026/02/25/wynn_resorts_shinyhunters/

[10] https://www.theregister.com/2026/02/20/shinyhunters_wynn_resorts/

[11] https://www.theregister.com/2026/02/18/adidas_investigates_thirdparty_data_breach/

[12] https://www.theregister.com/2026/02/18/shinyhunters_cargurus_breach/

[13] https://www.theregister.com/2024/02/20/nca_lockbit_takedown/

[14] https://www.theregister.com/2026/01/22/crims_compromised_energy_firms_microsoft/

[15] https://whitepapers.theregister.com/



Well it's a tough one

VoiceOfTruth

I agree, paying hackers/leakers is not a good idea. That is their 'business model' they depend on. But what if they just become 'vandals'? Just leaking over and over...

It's all very well for the police to say: do not pay. But their 'business' will not suffer.

Re: Just leaking over and over...

MiguelC

So, according to your expertise, leaking the same data multiple times is the big problem?

I know it is hard, but if no one ever payed digital ransoms, the business model would keel over. Then, the attacks that would subsist would mainly consist in sponsored ones, and be easier to identify as such

Re: Well it's a tough one

Doctor Syntax

Odido's business deserves to suffer on account of holding passport and driving licence numbers in the first place. These are surely not necessary for providing a telecoms service. However as customers have provided this data they must be OK with it unless Odido made them a requirement in which case they would appear to be in breach of GDPR.

"He stood up straight and looked the world squarely in the
fields and hills. To add weight to his words he stuck the
rabbit bone in his hair. He spread his arms out wide. `I
will go mad!' he announced."

- Arthur discovering a way of coping with life on
Prehistoric Earth.