
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Dutch police say the February 2026 breach at Dutch telecom Odido, where data on more than six million customers was stolen, was enabled by social engineering and phishing. Investigators cite a Dutch-speaking caller who allegedly posed as an Odido IT employee shortly before the intrusion, after which phishing led to the compromise and data theft.
According to Dutch police, the breach at telecom provider Odido began with a phone call to customer service shortly before the intrusion. During that call, a Dutch-speaking man posed as an internal IT employee. Odido has stated that the company was then compromised through phishing, after which attackers accessed a customer contact system and stole data belonging to more than six million customers. The cybercrime group ShinyHunters is described as having broken into Odido and accessed data from 6.2 million accounts.
Impersonating internal IT is effective because customer service and call center staff are trained to be helpful and responsive, especially when a request appears to come from within the organization. A caller claiming to have a vague 'system issue' can create just enough urgency to bypass normal skepticism, particularly if the request seems routine, such as looking up account details or adjusting settings. Once that initial vishing contact softened the target, a follow-up phishing message reportedly completed the compromise, showing how voice and email channels can be chained together in a single campaign.
The stolen data included names, addresses, phone numbers, email addresses, bank account details, dates of birth, and passport or ID numbers. Odido said passwords, call logs, and billing information were not affected. Even without credential exposure, this volume of personal data creates real risk for follow-on scams targeting affected customers.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Dutch police found a Dutch-speaking man called Odido customer service shortly before the hack and posed as an internal IT employee, and the company was then compromised through phishing.
Stolen data included names, addresses, phone numbers, email addresses, bank account details, dates of birth, and passport or ID numbers, though Odido said passwords were not affected.
The cybercrime group ShinyHunters is described as having broken into Odido and accessed data from 6.2 million accounts.
Train customer-service staff to treat internal-IT phone requests as high-risk, require call-back verification before any access-related action, and reinforce phishing defenses for staff with access to customer contact systems.
“Hi, this is IT from Odido…”, one phone call like that helped expose data from 6.2 million customer accounts. Dutch police say a Dutch-speaking man posed as an Odido IT employee, called customer service, then a phishing email did the rest, giving access to a customer contact system and all that personal data. Here’s the pattern: unverified ‘internal IT’ caller, vague urgent “system issue,” then an email pushing you to click a link and log in. That combo is exactly how Odido was compromised through phishing. If someone calls saying, “This is IT,” and wants access or changes, end the call and ring them back on an official number you look up yourself, no exceptions.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…