Dutch police are investigating ShinyHunters after a phone-based social engineering incident helped attackers break into Odido, the Netherlands’ largest mobile provider. Investigators say the caller persuaded an employee to log into a spoofed website, which was then used to steal data on more than 6.2 million people. The article also links ShinyHunters to high-profile data theft and extortion activity, including claims of a breach of an FBI jobs portal.
Key findings
- Dutch police circulated audio from a February 2026 call where a ShinyHunters member social engineered access to Odido.
- Attackers got an Odido employee to log into a spoofed website, then used that access to steal data on more than 6.2 million people.
- After an arrest tied to the ShinyHunters investigation, the group allegedly escalated, including claims of a breach of the FBI jobs application site (apply.fbijobs.gov).
- ShinyHunters publicly taunted authorities and claimed to have support structures for members, including arranging legal defense.
Who’s being targeted
- Commonly targeted roles: Service desk / Helpdesk, Customer support and call-center staff, IT operations, HR/Recruiting platform administrators, All employees with access to internal portals.
- Affected industries: Telecommunications, Government, Higher education, Technology, Healthcare, Agriculture, Transportation.
- Attack channels: vishing, website.
- Impersonated: Unspecified (ShinyHunters caller; impersonation details not provided in article).
Awareness takeaways
- Treat unexpected phone requests to ‘log in’ as suspicious, hang up and verify via a trusted internal number or ticketing system.
- Verify the website address before entering credentials; spoofed login pages are a common way attackers steal access.
- Assume a single successful social-engineering event can lead to large-scale data exposure; report suspected attempts immediately.
Red flags to watch for
- Being asked during a phone call to log in via a link/site the caller provides
- Login page domain/URL does not match the company’s official login domain (spoofed site)
- Unusual urgency or pressure to complete the login immediately
Read the video transcript
Dutch police just released audio of a call where ShinyHunters talked an Odido employee into a fake login, and 6.2 million people’s data walked out the door. On the call, the caller sounds legit, then says, “Just log in here so we can fix it,” and gives a link. The employee types corporate credentials into a spoofed login page, and that’s all ShinyHunters needed. Here’s the trap: a real colleague will never cold-call you and demand you log in through their link. If the URL isn’t your normal company login, that “quick fix” can become a 6.2‑million‑record breach. If anyone on the phone ever tells you where to log in, hang up, go to our usual login or helpdesk site yourself, and verify it there.