Incident notes · February 2026
A phishing email can be the first step, not the whole attack.
Reporting about the Odido breach shows how stolen credentials, a convincing phone call, and approval of a fraudulent login can work together.
What was reported
NOS reported that attackers obtained customer-service employees' passwords through phishing emails. They then called employees while posing as Odido's IT department and persuaded them to approve fraudulent login attempts, bypassing an additional security step. Multiple accounts were reportedly compromised and customer data was then collected automatically.
Read the original NOS reportWhy layered social engineering works
01
A message creates a believable reason to surrender credentials.
02
Phone call
A second channel and an internal identity create confidence and urgency.
03
Approval
The victim is guided into approving an action they did not initiate.
A practical pause
Treat unexpected requests for passwords, login approvals, payments, or sensitive information as a reason to stop. Contact the organization through a known number or internal channel, independently verify the request, and never approve an MFA prompt you did not initiate.
Where Maillume fits
Maillume can provide a second opinion on the email portion and make suspicious signals easier to see. It cannot verify a caller's identity, inspect an organization's internal systems, or guarantee that an email is safe. It should be one part of a broader verification process.
Check an email