ShinyHunters Talked Into Odido via Spoofed Login

Krebs on Security · Medium sophistication
Last updated September 28, 2026

Dutch police are investigating ShinyHunters after a phone-based social engineering incident helped attackers break into Odido, the Netherlands’ largest mobile provider. Investigators say the caller persuaded an employee to log into a spoofed website, which was then used to steal data on more than 6.2 million people. The article also links ShinyHunters to high-profile data theft and extortion activity, including claims of a breach of an FBI jobs portal.

Key findings

  • Dutch police circulated audio from a February 2026 call where a ShinyHunters member social engineered access to Odido.
  • Attackers got an Odido employee to log into a spoofed website, then used that access to steal data on more than 6.2 million people.
  • After an arrest tied to the ShinyHunters investigation, the group allegedly escalated, including claims of a breach of the FBI jobs application site (apply.fbijobs.gov).
  • ShinyHunters publicly taunted authorities and claimed to have support structures for members, including arranging legal defense.

Who’s being targeted

  • Commonly targeted roles: Service desk / Helpdesk, Customer support and call-center staff, IT operations, HR/Recruiting platform administrators, All employees with access to internal portals.
  • Affected industries: Telecommunications, Government, Higher education, Technology, Healthcare, Agriculture, Transportation.
  • Attack channels: vishing, website.
  • Impersonated: Unspecified (ShinyHunters caller; impersonation details not provided in article).

Awareness takeaways

  • Treat unexpected phone requests to ‘log in’ as suspicious, hang up and verify via a trusted internal number or ticketing system.
  • Verify the website address before entering credentials; spoofed login pages are a common way attackers steal access.
  • Assume a single successful social-engineering event can lead to large-scale data exposure; report suspected attempts immediately.

Red flags to watch for

  • Being asked during a phone call to log in via a link/site the caller provides
  • Login page domain/URL does not match the company’s official login domain (spoofed site)
  • Unusual urgency or pressure to complete the login immediately
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Dutch police just released audio of a call where ShinyHunters talked an Odido employee into a fake login, and 6.2 million people’s data walked out the door. On the call, the caller sounds legit, then says, “Just log in here so we can fix it,” and gives a link. The employee types corporate credentials into a spoofed login page, and that’s all ShinyHunters needed. Here’s the trap: a real colleague will never cold-call you and demand you log in through their link. If the URL isn’t your normal company login, that “quick fix” can become a 6.2‑million‑record breach. If anyone on the phone ever tells you where to log in, hang up, go to our usual login or helpdesk site yourself, and verify it there.

Similar attacks

Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest confirmed an employee was socially engineered into entering their password on a fake SSO page and approving an MFA push, giving attackers a brief “view only” session in the company’s identity dashboard. The attackers allegedly impersonated a named member of the security team over the…

August 25, 2026