9 min read

How a phone call allowed a hacker to steal millions of people's personal data

Financially motivated hackers are calling and tricking employees into handing over their passwords in highly effective voice-phishing attacks.
a photo looking down from the first-person perspective of a person's hands holding an iPhone taking a phone call, the caller ID says "Ruby".
Photo via Cottonbro Studios / Pexels

Earlier this year, Dutch telco Odido was breached by a hacker who stole the personal information of more than six million people in one of the largest thefts of data in the country's history. The breach relied on a phone call to a customer support agent and the use of a phishing page to capture their credentials, Dutch authorities have confirmed.

In a rare public disclosure since then, law enforcement have released a reconstruction of the call, featuring the Dutch-speaking hacker's real voice. The plea from the police is simple: Can the public help identify the hacker?

Troy Hunt in a post on X: "No AI, just a telephone and an old-school phishing page. That's it."

While there are abundant examples of phishing emails to peruse and investigate, it's rare to hear a call recording of a hacker carrying out a real-world voice phishing attack — also known as "vishing." As such, few get to hear how these calls actually happen, what to listen for, or how to defend against them. It's all the more important to know because phone calls remain an incredibly common way for hackers to break into companies. A successful phone call can allow a hacker to wedge their foot in the digital doorway of your network, then gain rapid access to your apps and data.

Odido isn't alone in falling victim to voice phishing. A Google employee was also tricked by a call-based hack that allowed hackers access to its Salesforce-hosted database of customer contact information. Tech giant Cisco, internet provider Charter, and phone company RingCentral were also breached in similar ways. This isn't a dig at any of these companies; this is to show that these are simple attacks and can happen anywhere, even at big tech firms, with alarming efficacy.

In this blog, we'll look at how some of these tactics work, why they are so effective, and what to look out for. This blog is drawn in part from my own reporting covering voice-based hacks over the years and hearing from hacking groups about how they target their victims, as well as other published research. You may be surprised to know that despite the marketing hype you might read, the top voice-phishing hackers do not use AI — but that's not to say AI won't help lower the bar for entry for some would-be hackers in the future.

If there's one thing I can't really hammer this point enough: Don't underestimate the threat from a single phone call. 

Astonishing admin subscribers, read on! If you're not a paid subscriber yet, come and join in for access to exclusive articles like this one.

This article is for subscribers on the Astonishing admins tier only