Dutch police have confirmed a ShinyHunters arrest: a 24-year-old man from Amsterdam, detained this month in an investigation into the hacking group. The statement runs to one sentence and does not mention Odido, the telecoms company whose February 2026 breach exposed 6.2 million people. The suspect was due at Rotterdam District Court on 29 September.
What the Police Actually Said
The confirmation from the Politie Landelijke Opsporing en Interventies, the Dutch national investigations service, was a single sentence issued on Monday 28 September 2026.
It reads: “It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters”. That is the whole of the official record on the arrest itself. Most outlets place the arrest on 15 September 2026, though police said only “this month”.
Separately, The Register quoted Stan Duijf, head of operations at the force’s national investigations and special operations arm, saying that arresting cybercrime suspects is an important intervention and that ShinyHunters “is responsible for a large number of national and international victims”. Police have not said what the man is specifically suspected of doing.
What Has Not Been Confirmed
The gap between that sentence and the headlines above it is unusually wide, so it is worth setting out plainly which claims carry official weight.
- Confirmed by police: a 24-year-old man from Amsterdam was arrested this month in a ShinyHunters investigation.
- Not stated by police: any link between this arrest and the Odido breach. The statement does not mention Odido at all.
- Not stated by police: the suspect’s identity. He has been named by journalists, not by the force or the prosecution service.
- Reported by a single outlet: that he is held in isolation while investigators work through two separate cases, and that he is not in fact suspected over Odido. Both come from The Register.
- Reported, not established: that a rival faction used an old alias to frame him, a theory attributed to unnamed sources.
Earlier reports also described the suspect as 23 and from a different town. The police statement gives 24 and Amsterdam, and that is the version on the record.
What the Odido Breach Exposed
Odido, the Dutch mobile operator formerly known as T-Mobile Netherlands, disclosed that attackers reached a customer contact system over the weekend of 7 and 8 February 2026.
The company put the number affected at roughly 6.2 million people across Odido and its subsidiary Ben. The breach index Have I Been Pwned, which added the incident on 26 February 2026, records 6.1 million accounts and six million unique email addresses published across four releases on consecutive days. Later reporting put the full dataset higher still, at more than 6.5 million people and 600,000 companies.
The data classes Have I Been Pwned lists are bank account numbers, customer service comments, dates of birth, driving licences, email addresses, genders, government-issued IDs, names, passport numbers, phone numbers and physical addresses. Odido’s own disclosure named names, addresses, phone numbers, email addresses, dates of birth, customer numbers, bank account numbers, and passport or driving licence numbers with their validity dates.
Odido told customers: “We cannot rule out that leaked data may be published or misused at some point. We advise all customers to remain very alert to unusual activities or contacts.” It refused to pay the ransom, and the attackers published the full dataset on 1 March 2026.
Identity-document numbers behave differently from passwords in a breach, because they cannot be rotated. Readers who followed our coverage of the Revolut breach that exposed passport copies and the IDScan breach, where credit freezes did not cover the exposure, will recognise the pattern.
How the Attackers Got In
The intrusion did not rely on a software flaw. According to the police account of the Odido case, it ran through a phone call.
- A Dutch-speaking man rang Odido’s customer service line and presented himself as an IT colleague.
- He persuaded an employee to enter their login credentials on a fake Odido sign-in page.
- He then had the employee supply a verification code, which defeated the multi-factor check.
- That access reached the customer contact system holding the records later published.
Odido’s own disclosure did not describe the attack method. The account above comes from the police, who released an audio recording of the caller during the investigation.
What ShinyHunters Has Said, and Why It Keeps Changing
The group’s public position on the arrested man has reversed.
After police released the audio recording, ShinyHunters indicated the voice belonged to one of its people and told the Dutch broadcaster BNR it had lawyers ready to represent him. Once the arrest became public, it told the same broadcaster: “That person has nothing to do with us.” It gave The Hacker News a longer version, saying the individual has no association with the group and accusing Dutch police of chasing attention after the embarrassment of the Odido hack.
ShinyHunters is an extortion group that steals corporate data and threatens to publish it unless paid. It also claimed an intrusion at the FBI’s job application site, apply.fbijobs.gov, which it first attributed to an unknown flaw in Oracle PeopleSoft; reporting since indicates the method was a URL-encoding trick that slipped past web filters guarding against CVE-2026-35273. Nothing the group says about its own membership can be treated as reliable.
Where the Case Stands Now
As of 30 September 2026, one arrest has been confirmed, no charges have been announced publicly, and police have not connected the case to Odido on the record.
The man was due before the Rotterdam District Court on Tuesday 29 September 2026. Neither the police nor the prosecution service has published what he is accused of, and no court outcome had been announced when this was written. For the 6.2 million people in the Odido dataset, the arrest changes nothing practical: the records were published in full seven months ago and cannot be recalled.
Frequently Asked Questions
Has Anyone Been Charged Over the Odido Hack?
No charge has been announced publicly. Dutch police confirmed an arrest in a ShinyHunters investigation but did not link it to Odido in their statement.
Who Is ShinyHunters?
An extortion group that breaks into company systems, steals customer databases and demands payment to keep them private. It claimed both the Odido breach and an intrusion at the FBI’s recruitment site.
Was My Data in the Odido Leak?
Have I Been Pwned added the breach on 26 February 2026, so an email address can be checked against its index there. The record covers 6.1 million accounts.
What Kind of Data Was Taken?
Names, addresses, phone numbers, email addresses, dates of birth, bank account numbers and identity-document numbers including passports and driving licences, along with customer service notes.
Does the Arrest Mean the Leaked Data Is Safe Now?
No. The complete dataset was published on 1 March 2026 and has circulated since. An arrest does not remove data that is already public.




