
QR-Code PDFs Steal Microsoft 365 Logins
Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…
Italy’s privacy regulator fined telecom operator WINDTRE €1.7M after two breaches where attackers used social engineering, posing as support technicians, to persuade store staff to grant system access. The intruders then pulled personal data for over 365,000 customers, including payment-related details for more than 41,000 people.
This incident did not involve malware or a software exploit. Instead, attackers impersonated support technicians and approached staff at two WINDTRE retail stores in person. By presenting themselves as authorized support personnel needing to resolve a system issue, they convinced employees to grant them access to internal company systems. Once inside, they were able to pull customer names and contact details, and in a substantial subset of cases, payment-related information.
The core weakness exploited here was trust in an unverified identity claim. Store staff had no reliable way, or no established process, to confirm that the person requesting access was actually an authorized technician. There was no mention of a ticket number, callback verification, or manager sign-off before access was granted. Italy's privacy regulator also pointed to underlying weaknesses in credential and certificate management, along with gaps in internal API protection, such as missing rate limiting or CAPTCHA on certain internal endpoints, that allowed the access to translate into a large-scale data pull once obtained.
These red flags apply broadly to retail store staff, customer service and contact center employees, IT support and helpdesk teams, and store or area managers, all of whom may be approached with a similar pretext.
Organizations, particularly in telecommunications and retail environments with distributed store locations, can reduce exposure to this style of attack by:
The WINDTRE case shows that a single successful impersonation at the store level can lead to data exposure affecting hundreds of thousands of customers, underscoring why frontline verification habits matter as much as technical defenses.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
They posed as support technicians and convinced staff at two WINDTRE stores to grant them access to company systems, without exploiting any software vulnerabilities.
Personal data for more than 365,000 customers was exfiltrated, and for 41,359 of those customers the stolen data included payment-related details such as IBAN numbers, partially masked card numbers, and card expiry dates.
No, the regulator noted the attackers relied on old-school social engineering rather than exploiting software vulnerabilities, though gaps in credential management and internal API protection also played a role.
Require staff to verify any tech support request with identity checks and a ticket number before granting system access, and train frontline teams that social engineering alone can lead to a full intrusion.
WINDTRE got hit with a €1.7 million fine because staff trusted the wrong “support technician.” Attackers just walked into two stores, said, “Hi, I’m a support technician, can you grant me access so I can fix an issue?” No hacking tools, just old-school social engineering. Staff granted access, and from there the intruders pulled data on over 365,000 customers, including IBANs and card details for more than 41,000 people. Your move: if anyone claims to be tech support, pause and verify their identity and ticket number through our official helpdesk before you grant a single click of access.

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk…

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting…

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow…

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…