Abused trust: phones, updates and helpdesks did the breaking in
A vishing crew talks its way past MFA at a Dutch telecom and reaches 6.2 million customers. Romania's national oil pipeline operator is breached via an infostealer on one admin's personal device. And Notepad++'s own update channel is hijacked by a state-sponsored espionage group.
Executive summary
- Trust was the attack surface. Attackers phoned Odido's customer-service staff posing as internal IT to defeat MFA and reach 6.2 million customers, hijacked Notepad++'s update channel to deliver a state-sponsored backdoor, and rode genuine Microsoft and PayPal notification emails past filters at a scale of 133,000 messages.
- One personal device breached national infrastructure. Romania's oil pipeline operator Conpet was compromised via an infostealer on an IT administrator's personal device, with the Qilin crew claiming nearly a terabyte of corporate data. OT systems stayed up, this time.
- The patch-to-exploit window is now measured in hours. BeyondTrust's pre-auth remote-access RCE went from advisory to mass exploitation in four days, within 24 hours of a public proof-of-concept, and Microsoft's February update fixed six zero-days already in use.
Key findings
Vishing past MFA: Odido breach reaches a third of the Netherlands
Attackers phished customer-service employees for credentials, then phoned them posing as internal IT to obtain secondary login approvals, defeating MFA by conversation rather than code. The CRM intrusion exposed names, addresses, dates of birth, IBANs and ID details for roughly 6.2 million customers.
Romania's pipeline operator breached via an infostealer on one personal device
Conpet, operator of Romania's 3,800 km crude pipeline network, confirmed an attack on its corporate IT after the Qilin crew claimed nearly 1 TB of data. Reporting traces the intrusion to a January infostealer infection on an IT administrator's personal device. SCADA and oil transport were unaffected, but the access path is the warning.
BeyondTrust remote-access RCE: advisory to mass exploitation in four days
A pre-authentication remote-code-execution flaw in Remote Support and Privileged Remote Access (CVSS 9.9) was disclosed on 6 February; exploitation began around 10 February, within a day of public proof-of-concept, with web shells, remote-access trojans and data theft observed on unpatched internet-facing instances. CISA added it to KEV on 13 February.
Notepad++ update channel hijacked by state-sponsored espionage group
The project disclosed its update hosting was compromised for months, with a China-linked espionage group selectively redirecting update requests from chosen IP ranges to trojanised installers carrying a backdoor. Confirmed targets included a government body, a financial organisation and an IT service provider. The updater has since been hardened with signature verification.
February Patch Tuesday: 58 flaws, six already exploited
Microsoft fixed 58 vulnerabilities of which six were exploited in the wild before the patch existed, spanning Windows Shell, MSHTML, Word, Desktop Window Manager and Remote Desktop privilege escalation. All six entered CISA KEV the same day, alongside earlier additions for FreePBX, GitLab and SolarWinds.
The broader pattern
- MFA is being defeated by conversation, not cryptography. Helpdesk and approval-fatigue attacks need procedural counters: call-back verification, no approvals initiated by inbound callers, and monitoring for unusual approval patterns.
- Personal devices are enterprise attack surface. An infostealer on one admin's home machine reached national pipeline infrastructure; credential hygiene has to extend to where credentials are actually typed.
- Leak-site claims are now themselves unreliable. Researchers exposed one new extortion brand fabricating most of its 200+ claimed victims with padded junk data, while Iron Mountain publicly disputed the scale of a claim against it. Verify before you panic, and before you pay.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Patch BeyondTrust Remote Support and February's six exploited zero-days now. All are on KEV with confirmed exploitation; internet-facing remote-access tooling first.
Harden helpdesk approval flows against vishing. No MFA approvals or resets initiated from inbound calls; call back on directory numbers and require manager confirmation.
Extend infostealer response to personal and BYOD devices. Force resets and session revocation for any corporate credential seen in stealer logs, wherever it was typed.
Pin and verify update channels for developer and admin utilities. The Notepad++ hijack redirected updates selectively by IP range; version-pin and validate signatures for tooling with broad install bases.
Verify extortion claims before reacting. Fabricated leak-site listings are now a fraud model; confirm data authenticity before notification, negotiation or payment decisions.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Every path in this fortnight ended in a valid session doing something no human should: a support account approving its own MFA push, an admin credential from a personal laptop touching pipeline IT, an updater fetching from new infrastructure. Blacklight baselines every identity and update channel it can see, correlates KEV entries against your estate the day they land, and its agents investigate and contain those sessions autonomously, with the reasoning trail ready for your team.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 3, 10 and 13 February 2026) · Microsoft February 2026 Patch Tuesday release notes · BeyondTrust advisory BT26-02 and Unit 42 exploitation research · Notepad++ project disclosure and vendor attribution research · public breach disclosures and security-press reporting (BleepingComputer, TechCrunch, The Register), 2 – 15 February 2026 · Check Point Research weekly threat intelligence (9 February 2026) · GuidePoint GRIT research on fabricated leak-site claims · MITRE ATT&CK v15.