-
A hacker claims a 100GB Odido data set is free to download, but the new claim remains unverified.
-
Odido confirms a February attack by ShinyHunters affected about 6.39 million people.
-
Dutch police are still probing the attack and will air a suspect’s voice on September 7.

A hacker claims to have released a huge data set linked to Dutch telecom provider Odido. The listing says the archive is about 3GB when packed and about 100GB after unpacking.
The post claims several download mirrors are available. It says the files are being shared for free instead of sold to buyers. The listing names ShinyHunters, which Odido says carried out its February attack.
There is a key warning, though. No trusted source has confirmed that this new 100GB archive is real. It is also unclear whether it is a new leak or a copy of data that’s already public after the February attack.
Odido Confirms a Large February Breach
Odido reported the attack on February 12. The company said criminals had got personal data from a customer help system. Odido now says about 6.39 million people, including current and past Odido and Ben customers, were hit. However, it didn’t affect Simpel customers.
The breach has been called the largest data leak in Dutch history, with ShinyHunters demanding over €1 million (approximately $1.1 million USD) and exposing data on more than 6.5 million people across 14 releases after Odido refused to pay.
The company says attackers called customer service while posing as IT staff. The first phone scam came on February 5. Another followed on February 6. Odido says staff spotted bad access and cut off the attackers. But one attack still led to data being stolen.
Odido names ShinyHunters as the threat group. The company says the group demanded an extortion payment, but Odido refused to pay.
Stolen Data Reached the Dark Web
The attackers later posted stolen Odido data online. Dutch police say the group put data from more than six million Odido customers on the dark web after Odido refused to pay.
Odido says the stolen data differed by person. It may include names, addresses, mobile numbers, customer numbers, email addresses, IBAN numbers, dates of birth, ID details, nationality and gender.
The company says the attack did not expose Mijn Odido passwords, call records, location data, billing data or scans of identity documents.
Odido does note one odd detail. The attack exposed a field called “password_c” from its customer contact system. The company says this was not a customer login password.
What the New 100GB Claim does not Prove
The new hacker post gives a much larger file size than earlier reports about the breach. It claims the archive is about 3GB packed and around 100GB after unpacking. It also claims that several mirrors host the files. But file size alone proves very little.
The listing does not show a data layout, a proven record count, or solid proof that the files came from Odido. It also does not explain whether the file holds customer records, system files, copies, or other material.
The archive could contain data stolen in February. It could be a new copy of data already in circulation. It could even contain other data given a false Odido label. Until researchers can check the files safely, the 100GB figure should remain a claim.
Police Probe is Still Active
The new police update shows that the Odido case has not ended. The Dutch police said the TV show Opsporing Verzocht would broadcast the suspect’s voice on September 7. Hopefully, the audience will be able to identify the caller, or the suspect will panic and turn themselves in.
Police say a Dutch-speaking man called Odido customer service and said he worked for the IT department. He told a worker that a problem needed fixing. The worker then gave the caller access to an internal system.
Police say the caller appears to have IT knowledge. A voice expert found that the recording contains a real human voice, rather than an AI voice.
Free Sharing Could Widen the Damage
If the new archive proves real, free sharing could make the situation harder to control. A file on several mirrors can spread quickly. Other users can copy and repost it. Removing one upload would not remove those copies.
That does not mean the new archive contains 100GB of unique Odido data. It may include copies or material that was already public. The distinction matters because the original attack already exposed millions of people. A new public file would mainly make access to that stolen information easier.
For now, the only valid facts remain that Odido suffered a large February attack, which affected about 6.39 million people, and the company blames ShinyHunters.
Dutch police also confirm that data from more than six million customers reached the dark web. The separate claim of a free 100GB database has not reached the same level of proof.
Users should not download or share stolen data. People hit by the attack should also watch for messages that use personal details to look genuine. As the police probe continues, the 100GB claim should remain unverified until outside proof shows what the files contain and where they came from.