At the beginning of this month, hackers published what appears to be the full remaining cache of stolen customer data from Dutch telecom provider Odido, following the telco’s decision not to pay ransom demand. The cache contains information on more than 6.5 million individuals and about 600,000 companies, includeing more than five million unique identification documents (eg, driver’s licenses and passports). The files also contain dates of birth, phone numbers and email addresses. Bank account numbers and internal customer service notes were withheld by the hackers, not said that such data would be kept “for their own use”.
And how did the hackers get in to this Aladdin’s Cave full of fantastically valuable data? Deep cover spies recuited years ago who are now in management positions? Sophisticated bugging equipement that bounces lasers off of windows to eavesdrop on snstivie conversations? No, of course not. They called Steve from Account while pretending to be from IT staff and tricked him into approving fraudulent logins, thus bypassing multi-factor authentication.