History
07/28/20260 new articles
The main change is a sharper attribution picture for the Odido breach: police now link it to suspected Dutch hackers while ShinyHunters separately claims responsibility, but the case remains unresolved. The rest of the story is largely a clarification and tightening of prior reporting, especially around Ajax remediation and the Finance Ministry impact.
07/27/20261 new articles
The update adds clearer attribution and scope details: police are now actively investigating the Odido intrusion and an arrest has been made in the Ajax case, while the reported extent of exposure is more specific but still partly unresolved. It also shifts the story toward remediation and uncertainty, with affected systems blocked or patched and final data-theft attribution still unconfirmed.
- Police linked the Odido intrusion to phishing using an impersonated IT employee.
- A 35-year-old suspect was arrested for repeated Ajax system access.
- Ajax exposure may reach more than 300,000 registered supporters.
- More than 42,000 Ajax season tickets may have been affected.
- Core Finance systems were reported unaffected after the intrusion.
07/25/20260 new articles
The main update is stronger attribution and evidence around the Odido breach, with police now linking suspected Dutch hackers to it and ShinyHunters publicly claiming the incident while releasing a much larger archive. The story also broadens slightly from breach mechanics to include survey evidence that Dutch consumers may be especially vulnerable to fraud using exposed personal data.
- Police linked suspected Dutch hackers to the Odido breach.
- ShinyHunters published an archive of more than 15 million records.
- Ajax impact estimates are now partly separate from its initial disclosure.
- ABN AMRO research highlighted underestimation of fraud risk among Dutch adults.
07/24/20260 new articles
The biggest update is the sharper attribution and scale around the Odido breach: it may have affected 6.2 million customers, with police tying it to social engineering and a separate actor claiming responsibility. The story also adds a concrete enforcement step in the Ajax case, where police arrested a suspect and Ajax patched exploitable API and shared-key weaknesses.
- Odido breach potentially affected 6.2 million customers.
- Police tied the Odido intrusion to impersonation-based social engineering.
- ShinyHunters separately claimed responsibility for the Odido breach.
- Police arrested a 35-year-old suspect over Ajax intrusions.
- Ajax patched vulnerabilities in APIs and shared access keys.
07/24/20264 new articles
The story has broadened from a few specific Dutch breaches into a wider pattern of recurring data exposures, with regulators now emphasizing rising fraud and account-takeover risks. A new telecom case, Odido, and ABN AMRO’s fraud-focused analysis make the privacy story feel more systemic and operationally urgent.
- Odido reported a large customer-data breach.
- The Dutch Data Protection Authority cites rising cyberattack notifications.
- AI-assisted phishing is increasingly linked to account takeover attempts.
- ABN AMRO warns breach data is being reused for fraud.
- ShinyHunters is tied to leaked Odido data.
05/30/20263 new articles
The story broadened from Dutch public-sector cyber incidents into a wider pattern that now includes AFC Ajax’s supporter-data exposure and vulnerability exploitation. The new version also adds clearer emphasis on partial containment, patching, and regulatory notifications rather than confirmed theft.
- AFC Ajax disclosed supporter-data exposure through app and website vulnerabilities.
- Ticketing and stadium-ban records may have been exposed in the Ajax incident.
- Dutch Data Protection Authority notifications are explicitly part of the response.
- Attack paths now include phishing, unauthorized access, and exposed APIs/shared access keys.
- The reporting window extends from March to May 2026.
05/11/2026Topic Formed
Dutch government institutions are dealing with multiple cyber incidents that triggered access blocking, forensic investigation, and partial service shutdowns. The strongest signal is not confirmed data theft, but uncertain breach scope and operational disruption across finance and police systems.