
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Italy’s privacy regulator fined telecom operator WINDTRE after two breaches where attackers used simple social engineering, not hacking tools. The attackers posed as support technicians and talked retail store staff into giving them system access, leading to theft of customer data. The case shows how frontline staff and store procedures can be the weakest link, even in large telecoms.
Italy's data protection authority fined telecom operator WINDTRE 1.7 million euros following two breaches that impacted personal data belonging to more than 365,000 customers. Notably, the regulator found that neither breach involved hacking tools or software exploitation. Instead, attackers posed as support technicians and convinced staff at two WINDTRE retail stores to grant them system access. That access ultimately led to the theft of customer data.
The pretext was simple: someone shows up claiming to be from support and asks for access to fix a system issue. In a busy retail environment, staff are often trained to be helpful and to resolve technical problems quickly, which makes an unscheduled visit from a claimed technician easy to accommodate rather than question. The regulator explicitly noted that both incidents relied on old-school social engineering rather than software exploitation, underscoring that the weak point was human trust and process, not a technical vulnerability.
A few warning signs stand out in this scenario:
Any of these alone should prompt a pause. Together, they describe exactly the kind of encounter that led to unauthorized system access at WINDTRE stores.
Organizations with retail, storefront, or field-facing operations can reduce this risk by treating
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers posed as support technicians and convinced staff at two WINDTRE retail stores to grant them system access, without using any software exploits.
No, the regulator described it as old-school social engineering rather than software exploitation, and the incident is rated low sophistication.
Italy's data protection authority fined WINDTRE 1.7 million euros after two breaches affecting more than 365,000 customers, treating the repeat nature of the incidents as an aggravating factor.
Retail store staff, store managers, customer service and helpdesk teams, IT support teams, and security and compliance leadership are all named as relevant audiences.
In Italy, WINDTRE got hit with a €1.7 million fine… not for hacking, but for someone saying, “Hi, I’m from support.” At two WINDTRE retail stores, someone walked in, posed as a support technician, and talked staff into granting system access, no malware, just persuasion. Here’s the trap: unscheduled visit, “urgent” system issue, and pressure to bypass normal approvals. That’s how over 365,000 customers’ data walked out the door. Your move: if anyone says, “I’m from support, let me in,” pause, and call the official helpdesk to confirm before you grant a single click of access.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

Researchers report a real North Korea–linked social engineering campaign where attackers posed as recruiters and sent fake job offers and coding assessments.…

Microsoft reports attackers linked to ShinyHunters spent a year getting into corporate Salesforce data without exploiting Salesforce bugs. One key method was…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…