Spot the phish

    A second of doubt is cheaper than a week of repairs

    Phishing stopped being that e-mail full of spelling mistakes a long time ago. It comes as a calendar invitation, a call from 'the bank', a chat message from 'the helpdesk' or a video call with your 'director'. Learn the tricks, practise with copied messages and read what happened to those who did fall for it.

    The tricks

    Four buttons fraudsters press

    Hurry

    "Within 24 hours, or else..." People in a hurry check nothing. That's why fraudsters always rush you.

    Authority

    The bank, the tax office, the director, the helpdesk. A title or a logo is easy to copy, and so are a voice and a face.

    Curiosity

    A parcel, a shared document, a refund, a photo of you. You just want to take a quick look.

    Helpfulness

    A colleague in trouble, a customer who wants to pay quickly, 'the helpdesk' improving your security. Your kindness is used against you.

    Practise

    Phish or not? The big round

    Six messages a round, a different mix every time. They are made up, but every fake copies a real attack. After you answer you see what to look out for, and for every fake what happened in real life.

    Text message 1 of 6

    From: Delivery Service

    Your parcel could not be delivered. Pay 1.95 euros shipping within 24 hours via track-parcel.example, or it goes back to the sender.

    Show the answer

    Phishing. A small amount makes it look harmless, but they're after your card details. Couriers don't ask for money through a link in a text.

    How you can tell:

    • A parcel and you don't know who it's from.
    • Hurry: within 24 hours.
    • Paying through a link to an unknown site.

    Real story: 130,000 text messages in a few days

    E-mail 2 of 6

    From: Safe Bank <[email protected]>

    Your account will be blocked

    We noticed unusual activity. Confirm your details within 2 hours using the button below, or we will block your account.

    Show the answer

    Phishing. A bank doesn't ask you to confirm your details through a button in an e-mail. In doubt? Open your banking app yourself.

    How you can tell:

    • A threat: or we block your account.
    • Hurry: within 2 hours.
    • Confirming your details through a button in an e-mail.

    Real story: 'This is your bank's fraud department'

    E-mail 3 of 6

    From: IT helpdesk <[email protected]>

    Your mailbox is 99% full

    Soon you will no longer receive e-mail. Log in on this page now to request extra space for free.

    Show the answer

    Phishing. Your login page never comes from an e-mail. You get more space in your own mail app or through your own IT partner.

    How you can tell:

    • A vague 'helpdesk' you don't know.
    • Logging in through a link in the e-mail.
    • A threat: no more e-mail.

    Real story: A phishing e-mail in October, a university down at Christmas

    E-mail 4 of 6

    You're a member of the volleyball club.

    From: Triangle Volleyball Club <[email protected]>

    Saturday's programme

    Hi! On Saturday we play at home at 2 pm. Coming to watch? You can unsubscribe from this newsletter at the bottom of this e-mail.

    Show the answer

    Real. Exactly what you expected from your club. Nothing wrong here.

    Why it checks out:

    • A sender you know.
    • No request for money, details or a login.

    Calendar invitation 5 of 6

    Organiser: Billing Team <[email protected]>

    Invitation: discussion of outstanding invoice Q3

    When
    Thu 10:00 - 10:30
    Location
    Read the document first: docs-share.example/q3

    You have been invited to a meeting about an outstanding invoice. Please read the shared document beforehand. This event is already in your calendar.

    Show the answer

    Phishing. Calendar invitations slip past spam filters more often and appear in your calendar by themselves. Don't open documents from an invitation sent by someone you don't know.

    How you can tell:

    • It was already in your calendar without you accepting anything: that's how invitations work, fake ones too.
    • You don't know the organiser.
    • The 'location' is a link to a document on an unknown site.
    • An outstanding invoice makes you curious and a little worried.

    Real story: Fake invitations that turned up in your calendar by themselves

    Text message 6 of 6

    You've just set up your banking app on your new phone.

    From: Your bank

    Your banking app has just been activated on a new device. Wasn't you? Call us on the number on the back of your bank card.

    Show the answer

    Real. A good notification sends you to a number you already have, not to a link.

    Why it checks out:

    • It confirms something you just did yourself.
    • No link: you call yourself, on a number you already have.

    Every round deals new messages from 30. All made up, but every phish copies the trick of a real attack.

    The check

    How to check a message in thirty seconds

    • Was I expecting this? An invoice, a parcel or an invitation you weren't expecting is suspicious.
    • Who is the sender really? Look at the address, the number or the domain, not just the name.
    • Is there rush or a threat? Then it's time to slow down.
    • What am I asked to do? Click, log in, pay, pass on a code or install something? Extra care.
    • Check it another way. Call yourself, on a number you look up, or open the app yourself.

    In doubt? Then do nothing and check. A real bank, supplier or colleague is fine with that.

    How it feels

    Tuesday, 16:12

    Based on a real case; names and details changed.

    The new account numberBased on a real case. Names and details changed.
    1. Mila (accounts)

      Joost, the wholesaler has a new account number. It came by e-mail this morning, with a neat letter attached.

    2. Joost (owner)

      OK. Does it say why?

    3. Mila (accounts)

      'New payment route as instructed by management.' A Spanish bank, bit odd. But it's from Petra's usual address there.

    4. Mila (accounts):

      They've already asked twice whether I've updated it. Very polite, mind.

    5. Joost (owner)

      Go ahead and change it, then that's sorted.

    6. Joost (owner):

      Mila, the wholesaler just rang. They haven't received a thing from us since December.

    7. Mila (accounts)

      But I've paid everything! To the new number.

    8. Joost (owner)

      That number wasn't theirs. Petra's mailbox had been hacked, and our confirmation was tucked away in a hidden folder there. She never saw it.

    9. Mila (accounts)

      So that money's gone? And we have to pay again?

    10. Joost (owner)

      Looks like it. New rule: account number changed? Call first, on the number we already had.

    What really happened (with the source)

    It really happened

    They fell for it, and this is what it cost

    Click for the summary. Below it you'll always find the link to the full story.

    • 2026

      A fake IT colleague calls customer service

      Customer service staff at a large Dutch telecoms provider, and millions of customers

      Cost: Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.

      What happened

    • 2019

      'Our new payment route', from a hacked mailbox

      The accounts payable team of a large Dutch online shop, and a regular supplier

      Cost: 751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.

      What happened

    • 2024

      The finance director on the video call was fake

      A finance employee at the Hong Kong office of an international engineering firm

      Cost: Some 200 million Hong Kong dollars, about 25.6 million US dollars.

      What happened

    • 2025

      'This is your bank's fraud department'

      Thousands of Dutch bank customers

      Cost: In the Netherlands in 2025, 25.8 million euros from just under 5,900 victims. Just over 45 per cent was reimbursed as a goodwill gesture.

      What happened

    • 2018

      A secret takeover in Dubai, paid in six instalments

      The managing director and finance director of a Dutch cinema chain

      Cost: More than 19.2 million euros. Both directors lost their jobs.

      What happened

    • 2019

      A phishing e-mail in October, a university down at Christmas

      A Dutch university

      Cost: A ransom of 30 bitcoin, almost 200,000 euros at the time. Dozens of staff worked through the Christmas holidays.

      What happened

    Questions

    And if you did click?

    I clicked a link but didn't fill anything in.

    Close the page. Keep an eye on your device for the next few days and make sure your updates and virus scanner are up to date. In doubt? Send us a message.

    I entered my password.

    Change it straight away, and everywhere else you use the same password. Turn on two-step verification and check whether new rules appeared in your mailbox that forward e-mail.

    I transferred money or gave my bank details.

    Call your bank straight away, on the number on your bank card or in your banking app. The sooner, the better. Then report it to the police. Also read first aid after a hack.

    Can you train my team?

    Yes. In a practical session we practise with examples like the ones above, tuned to your e-mail, your bank and your customers.

    Press play

    A sharp team, without a dull course

    A short, practical phishing training with real examples. After that nobody clicks just like that. Or first read in the Evo-log how to spot phishing in 30 seconds.

    Real story - 2020

    130,000 text messages in a few days

    Tens of thousands of recipients in the Netherlands

    What happened
    In September 2020 a 22-year-old man sent almost 130,000 text messages in a few days, in the name of the Dutch tax office, PostNL, UPS and DigiD, among others. The links led to fake payment pages, where he also captured people's bank login details.
    Why it worked
    Familiar names and a payment link you quickly tap on your phone.
    What it cost
    According to the Dutch Public Prosecution Service, 60,000 victims of attempted fraud. The man was sentenced to 4.5 years in prison.
    What would have stopped it
    Never pay or log in via a link in a text. The Dutch tax office doesn't send direct payment requests. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A secret takeover in Dubai, paid in six instalments

    The managing director and finance director of a Dutch cinema chain

    What happened
    In March 2018 the Dutch managing director received e-mails that seemed to come from the head of the French parent company. They were about a strictly confidential takeover of a company in Dubai; an adviser from a big accountancy firm would be in touch. Contact was only allowed through 'my personal e-mail', never by phone, and not even colleagues could know. Six payments to Dubai followed within three weeks. It only came out when the French head office asked questions about the money.
    Why it worked
    Authority, urgency and above all secrecy that blocked every normal check: no phone calls, not a word to colleagues. There were doubts ('A strange process. Never seen anything like it'), but a phone call was brushed off and nobody rang the real chief executive on a known number.
    What it cost
    More than 19.2 million euros. Both directors lost their jobs.
    What would have stopped it
    Secrecy plus urgency plus a new account means: stop. Call the requester back on a number you already had, never one from the e-mail. No payment instruction may forbid you to involve a colleague.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2025

    'This is your bank's fraud department'

    Thousands of Dutch bank customers

    What happened
    A 'bank employee' calls, sometimes with the bank's real number on screen. Something odd is happening on your account and your money has to go to a 'safe account' for now. Or your card is no longer safe and a courier will collect it. Sometimes you're asked to install a program such as AnyDesk so they can 'help'. The callers often already know your name, your account number and sometimes even your latest payments.
    Why it worked
    Fear, urgency and authority, made believable with data from earlier phishing or leaks and a spoofed phone number. Sometimes it starts with a phishing e-mail, after which 'the bank' calls about a threat to your account.
    What it cost
    In the Netherlands in 2025, 25.8 million euros from just under 5,900 victims. Just over 45 per cent was reimbursed as a goodwill gesture.
    What would have stopped it
    Your bank never asks you to move money to a 'safe account', never collects your card and never asks for remote access. Hang up and call the number on the back of your card yourself.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    'Hi mum, this is my new number'

    Dutch people, often parents, who get a message from 'someone they know'

    What happened
    A message from an unknown number: 'mum my phone is broken, this is my new number'. The old number can be deleted. Then comes a problem that needs solving fast, and it takes money. The profile photo comes from social media, and calling is 'not possible right now'. Sometimes fraudsters even use a cloned voice.
    Why it worked
    Emotion (your child in trouble), urgency and a story that explains the unknown number straight away.
    What it cost
    Of the Dutch people who fell victim to phishing in 2024, 9 per cent were victims of this friend-in-need fraud. No total amount is known.
    What would have stopped it
    Never pay after a message: first call the old number in your own contacts. Agree on a family code word for payment requests.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2018

    A fake MijnOverheid e-mail, and the text code with it

    203 Dutch DigiD users

    What happened
    In June 2018 people received an e-mail with a link to a fake version of MijnOverheid, the Dutch government's message box. Anyone who logged in there with DigiD also handed over the text code. A script used those details straight away to log in for real and search MijnOverheid. A second wave followed in December: an official letter was supposedly waiting.
    Why it worked
    Trust in the government, and a fake site that passed the text code straight on. Real e-mails from MijnOverheid never contain a link.
    What it cost
    203 DigiD accounts were deleted and personal data was probably collected. In the second wave, according to DutchNews, 361 people fell for it.
    What would have stopped it
    Never log in via a link or QR code in a message that seems to come from DigiD, MijnOverheid or the tax office. Open the app yourself or type the address in yourself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    A phishing e-mail in October, a university down at Christmas

    A Dutch university

    What happened
    In mid-October 2019 phishing e-mails were opened on two workstations. Several variants had been sent, and a report about one variant wasn't properly followed up. The attackers moved through the network for more than two months. On 23 December they encrypted 267 Windows servers, including e-mail servers, file servers and a number of backup servers.
    Why it worked
    About 20 per cent of users open phishing e-mails, the university wrote itself. An administrator account was also used for routine maintenance, a server was missing updates and the network was fairly open. The online backups could be encrypted too.
    What it cost
    A ransom of 30 bitcoin, almost 200,000 euros at the time. Dozens of staff worked through the Christmas holidays.
    What would have stopped it
    Report every phishing e-mail and make sure every report gets followed up: one missed variant was enough. Keep backups offline and admin accounts separate.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Fake invitations that turned up in your calendar by themselves

    Staff at around 300 organisations (not named)

    What happened
    Criminals sent e-mails that looked like a Google Calendar invitation from someone the victim knew. The invitation held a link to a Google Form or Google Drawing, containing yet another button disguised as a reCAPTCHA or support button. That led to a fake page where people entered personal details and eventually payment details.
    Why it worked
    Trust in Google and in ordinary calendar notifications, and a sender who seemed familiar. When security tools started flagging the invitations, the criminals switched from forms to drawings.
    What it cost
    More than 4,000 of these e-mails in four weeks, at around 300 organisations. Criminals can use the details for credit card fraud; no damage figure has been published.
    What would have stopped it
    Don't click links in an unexpected invitation, even if it's already in your calendar. Open documents only where they belong. In Google Calendar you can make only invitations from known senders appear automatically.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    First hundreds of spam e-mails, then 'the helpdesk' calls

    Staff at various organisations (not named)

    What happened
    The attackers signed their target's e-mail address up to a whole series of newsletters, so the mailbox overflowed. Then they called, or sent a Teams message under names such as 'Help Desk' or 'IT Support', offering to sort out the spam. The victim was asked to open Quick Assist and type in a code the 'helpdesk' gave them. That handed the attackers the computer.
    Why it worked
    The attacker creates the problem first, then offers the fix at exactly the right moment. Quick Assist is a genuine Windows tool, and the Teams names look internal.
    What it cost
    Microsoft gives no amount. Once in, the attackers installed more tools and in several cases spread ransomware across the whole network.
    What would have stopped it
    Only let someone into your computer if you contacted your own IT partner yourself. A sudden spam flood followed by a helpful call is a warning sign in itself.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2022

    Prompt after prompt, until someone pressed Approve

    A contractor working for a large US ride-hailing company

    What happened
    The attacker had probably bought the contractor's password on the dark web, after a personal device of the contractor's was infected with malware. The attacker then tried to log in again and again. Each time, the contractor got a request to approve the sign-in, until eventually one was approved. According to the attacker, a WhatsApp message from 'IT' also arrived: approve one and they'll stop.
    Why it worked
    Fatigue and annoyance, plus a fake explanation from 'IT'. A simple Approve or Deny button, with no number to match.
    What it cost
    No amount published. But the attacker got into tools including Slack, G Suite and an internal invoice system, and posted a message in a company-wide Slack channel.
    What would have stopped it
    Never approve a sign-in request you didn't start. A string of requests means someone has your password: report it at once and change it. IT never asks you to approve anything.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    The finance director on the video call was fake

    A finance employee at the Hong Kong office of an international engineering firm

    What happened
    It started with a message that seemed to come from the chief financial officer in the UK, about a secret transaction. At first the employee suspected phishing. Then came a video call with the CFO and other colleagues, who looked and sounded just like the people the employee knew. According to the police, everyone on that call was fake except the employee. Fifteen transfers followed. It only came out when the employee checked with head office.
    Why it worked
    Authority (the CFO), secrecy and a group of familiar faces removed the doubt. Faces and voices were faked using public videos of the real people. One employee could make fifteen payments without a call-back check or a second approval.
    What it cost
    Some 200 million Hong Kong dollars, about 25.6 million US dollars.
    What would have stopped it
    Never act on a payment instruction from a call or chat until you've called the requester back yourself, on a number you already had. A 'secret' deal that skips the normal route is a stop sign, even when the faces look right.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Our new payment route', from a hacked mailbox

    The accounts payable team of a large Dutch online shop, and a regular supplier

    What happened
    In late November 2019 an e-mail arrived from the real address of an employee at a regular supplier: 'Attached you will find our new payment route as instructed by management.' The neat letter gave a Spanish bank account. Two polite reminders asked whether the records had been updated yet. The account number was changed and from then on the payments went to the fraudsters. In mid-January the supplier asked where its money was.
    Why it worked
    The e-mail really came from the supplier's mailbox, with the real logo. Rules in that hacked mailbox hid every reply in a hidden folder, so the supplier never saw the confirmation. The judge said the shop should have shown 'healthy suspicion': a Dutch company suddenly using a Spanish account, clumsy wording and a well-known trick.
    What it cost
    751,493 euros went to the fraudsters. The court ruled that the shop had to pay the supplier again.
    What would have stopped it
    Never change an account number because of an e-mail. Call a contact you already know on a number you already had. And protect your own mailbox with two-step verification; check it for rules you didn't create.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    Fake QR stickers on parking meters

    Drivers in Dutch and Belgian cities

    What happened
    Neat stickers saying 'Scan to pay' appeared on parking meters, over or next to the real information. Anyone who scanned ended up on a site that looked like a parking app and asked for bank details. Councils removed the stickers and issued warnings. In Brussels the police arrested a man carrying 160 of these stickers.
    Why it worked
    A sticker looks official and convenient, and a QR code hides where it leads.
    What it cost
    No total known. Anyone who paid handed card or bank details to fraudsters.
    What would have stopped it
    Pay for parking at the machine itself or through the app you already have. Check the address in your browser after every scan.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2026

    A fake IT colleague calls customer service

    Customer service staff at a large Dutch telecoms provider, and millions of customers

    What happened
    In early February 2026 a man speaking good Dutch phoned customer service. He posed as a colleague from the IT department: a problem needed fixing, and for that the employee had to log in to an internal system. On a fake login page the employee entered a username, a password and a verification code. The data of millions of customers was then downloaded in a short time. Later, fraudsters called customers about 'compensation' for the breach and asked them for a text code.
    Why it worked
    A colleague from IT, a problem that needs fixing now, and English IT jargon sprinkled through the Dutch. The extra security step was bypassed because the employee handed over the code. According to NOS, access was also set up too broadly and no alarm went off during the large download. The company only learned of the theft when the criminals got in touch themselves.
    What it cost
    Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.
    What would have stopped it
    Real IT never asks you to log in through a link they give you on the phone, and never asks for your code. Hang up and call the service desk back on the internal number. As a customer: your provider doesn't call about compensation, and you never pass on a text code.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2025

    'Your SIM card is expiring', and your number belongs to someone else

    Customers of two large Dutch providers

    What happened
    In 2025 customers got texts and calls in the name of their provider: the SIM card was about to expire, had to be 'validated' or, 'due to new legislation', switched to an eSIM. Via a link they entered their details, sometimes even their citizen service number (BSN). Some were also asked to forward a genuine e-mail from the provider or to delete the provider's app. After that, criminals had the SIM card.
    Why it worked
    A technical-sounding problem, 'new legislation' as the reason, and small steps that each seem harmless on their own.
    What it cost
    No numbers or amounts known. With the hijacked SIM cards, the criminals sent fake texts in bulk to new victims, from the victim's own number.
    What would have stopped it
    Your provider never gets in touch because your SIM card is expiring or needs validating. Delete the message or hang up. Lost control of your SIM card? Call your provider at once.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2024

    A Teams invitation with a code, on the real Microsoft site

    Staff at governments, NGOs, IT firms and other organisations in Europe and beyond

    What happened
    The attackers first made contact via WhatsApp, Signal or Teams, posing as someone who mattered to the target. After some friendly contact came an invitation to a Teams meeting. To join, the target had to enter a code on a Microsoft sign-in page. The attacker had generated that code, and that gave the attacker access to the account.
    Why it worked
    Build trust first, then use a sign-in page that really is Microsoft's: there's no fake address to spot. The victim does the two-step verification themselves, on the attacker's behalf.
    What it cost
    No amount published. The attackers searched mailboxes for words such as 'password' and 'admin', took e-mails and sent new phishing to colleagues from the hijacked account.
    What would have stopped it
    Never enter a code on a sign-in page because a chat or invitation asks you to. Organisations: switch off this way of signing in (device code) wherever nobody needs it.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    The hotel's account hijacked, the guests scammed

    Hotels that take bookings through a large booking platform, and their guests

    What happened
    A hotel received an e-mail from a 'former guest' who had supposedly left a passport behind, with a link to photos of it. The link delivered malware that stole the hotel's login for the booking platform. With it the fraudsters read the real reservations and messaged guests: their payment or booking just needed 'verifying', via a link.
    Why it worked
    Hotel staff want to help guests, and the guests got messages with their real booking dates, sometimes even through the real platform.
    What it cost
    In Singapore at least 30 guests lost 41,000 dollars between them. Dutch travellers lost money and card details too.
    What would have stopped it
    Guests: never re-enter your card details via a link in a message; check in the app or call the hotel. Hotels: don't open 'passport photos' from strangers, and turn on two-step verification for your platform account.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2019

    'Scan this QR code to receive your money'

    People selling things on an online marketplace

    What happened
    The seller gets a WhatsApp message from a 'buyer', who says they're paying from a business account and sends a QR code to scan with the banking app to 'accept' the money. In reality the seller was linking a second device to their own bank account: the fraudster's.
    Why it worked
    A QR code doesn't show where it leads, and it was a genuine feature of the victim's own banking app. That made it feel safe.
    What it cost
    Several hundred reports; in some cases fraudsters got away with thousands of euros. The bank refused at first, but later reimbursed all the damage after all.
    What would have stopped it
    You never scan a QR code to receive money. Someone sending you money only needs your account number.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2023

    A call to the helpdesk: 'I can't log in'

    The IT helpdesk of a large US casino and hotel group, and that of a cleaning-products maker

    What happened
    According to the attackers themselves, they looked up an employee on LinkedIn and called the helpdesk as that person to get into the account. At the second company, attackers called the outsourced service desk and asked for new passwords. According to that company's lawsuit, the service desk handed them over without the usual checks: 'Oh, ok. Ok. So let me provide the password to you ok?'
    Why it worked
    A helpdesk wants to help quickly, and the check on who was calling relied on facts an attacker can look up. Or it didn't happen at all.
    What it cost
    The casino group reported a negative impact of about 100 million dollars on its results. The manufacturer is claiming 380 million dollars in damages in its lawsuit.
    What would have stopped it
    Never reset a password or two-step verification on the strength of a phone call alone: call back on a number you already had, or check with the manager. Got a reset message you didn't ask for? Report it at once.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.