The breach matters because the access path looks procedural, not technical. If a caller can convince support staff they are internal IT, the helpdesk becomes the entry point and the normal customer-verification process becomes the thing that opens the door.
Dutch police said they found evidence that a Dutch-speaking caller posed as Odido IT staff before the February incident that exposed data on more than 6 million customers. That makes the social-engineering route concrete, and it points to customer-service and CRM access as the real blast radius.
For telecoms, the risk sits in any workflow where support staff can grant access or reset accounts after verbal identity checks. The problem persists even when perimeter defenses hold, because the attacker is using the organization’s own trust process against it.