ShinyHunters Leak 2M Records From Dutch Telecom Odido, Claim 21M Stolen
2026-03-04T21:05:05Z•ecbfbd4d8087056abfb8b0c49dd48ceab8f31f599e06bce0398e71e4d3752097
1CampaignAI-agent-hijackAeternumAvastChatGPT-accessClawJackedEntraIDMFA-bypass-riskOAuth-consentOdidoOpenClawPolygon-blockchainShinyHuntersVulnCheckad-cloakingblockchain-C2botnetbrowser-vulnerabilitydata-breachfake-websitephishingphishing-scamtelecom-breachthreat-intel-reporting','US-sanctions','Operation-Zero','exploitvulnerability-trends
What happened
Multiple high-impact incidents and research findings: ShinyHunters leaked 2 million Odido customer records (claiming up to 21M stolen) after a ransom refusal; Oasis Security disclosed a critical “ClawJacked” vulnerability in OpenClaw that can let websites hijack AI agents via a browser tab; Varonis revealed 1Campaign, an ad-cloaking platform used to hide phishing pages from Google reviewers; Qrator spotted the Aeternum botnet using the Polygon blockchain for resilient C2; fraudsters cloned Avast to run a €499 refund phishing scam targeting French users; Entra ID OAuth consent flows can grant e
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- ecbfbd4d8087056abfb8b0c49dd48ceab8f31f599e06bce0398e71e4d3752097
- Enrichment time
- 2026-03-04T21:05:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.