How a phone call allowed a hacker to steal millions of people's personal data
Earlier this year, Dutch telco Odido was breached by a hacker who stole the personal information of more than six million people in one of the largest thefts of data in the country's history. The breach relied on a phone call to a customer support agent and the use of a phishing page to capture their credentials, Dutch authorities have confirmed.
In a rare public disclosure since then, law enforcement have released a reconstruction of the call, featuring the Dutch-speaking hacker's real voice. The plea from the police is simple: Can the public help identify the hacker?
No AI, just a telephone and an old-school phishing page. That's it. https://t.co/blEw3qd5Ca
— Troy Hunt (@troyhunt) September 7, 2026
Troy Hunt in a post on X: "No AI, just a telephone and an old-school phishing page. That's it."
While there are abundant examples of phishing emails to peruse and investigate, it's rare to hear a call recording of a hacker carrying out a real-world voice phishing attack — also known as "vishing." As such, few get to hear how these calls actually happen, what to listen for, or how to defend against them. It's all the more important to know because phone calls remain an incredibly common way for hackers to break into companies. A successful phone call can allow a hacker to wedge their foot in the digital doorway of your network, then gain rapid access to your apps and data.
Odido isn't alone in falling victim to voice phishing. A Google employee was also tricked by a call-based hack that allowed hackers access to its Salesforce-hosted database of customer contact information. Tech giant Cisco, internet provider Charter, and phone company RingCentral were also breached in similar ways. This isn't a dig at any of these companies; this is to show that these are simple attacks and can happen anywhere, even at big tech firms, with alarming efficacy.
In this blog, we'll look at how some of these tactics work, why they are so effective, and what to look out for. This blog is drawn in part from my own reporting covering voice-based hacks over the years and hearing from hacking groups about how they target their victims, as well as other published research. You may be surprised to know that despite the marketing hype you might read, the top voice-phishing hackers do not use AI — but that's not to say AI won't help lower the bar for entry for some would-be hackers in the future.
If there's one thing I can't really hammer this point enough: Don't underestimate the threat from a single phone call.
Astonishing admin subscribers, read on! If you're not a paid subscriber yet, come and join in for access to exclusive articles like this one.