Vishing attack

One Phone Call, Millions of Records: Why Cleveland Businesses Can’t Afford to Ignore Vishing Attacks This Summer

June 4, 2026|

Summer in Cleveland means packed patios on East 4th Street, busy shipping lanes on Lake Erie, and — if your business isn’t careful — cybercriminals quietly burning through your company’s data while everyone is focused on the season’s rush. A recent high-profile breach at ADT is a stark reminder that the most dangerous attacks don’t always come through a firewall. Sometimes, they come through a phone call.

One Call. Millions of Records.

Security researchers and the cybercrime group ShinyHunters have both confirmed that a major data breach at ADT started with a vishing attack — short for voice phishing. A threat actor called an ADT employee, impersonated a trusted source, and convinced that employee to hand over credentials to their Okta single sign-on (SSO) account. Once inside, the attackers pivoted directly into ADT’s Salesforce environment and walked out with data tied to an estimated 5.5 million customers: names, addresses, phone numbers, and partial Social Security numbers.

No sophisticated malware. No zero-day exploit. Just a convincing phone call — and one employee who had no reason to suspect it wasn’t legitimate.

What is a Vishing Attack?

If you’ve heard of phishing emails, vishing is the voice-based cousin. It’s a social engineering technique where a cybercriminal calls an employee — often posing as IT support, a vendor, or an internal department — and manipulates them into revealing login credentials, approving a multi-factor authentication (MFA) request, or transferring access to a sensitive system.

Modern vishing campaigns are sophisticated. Attackers research their targets on LinkedIn, use spoofed caller ID numbers that appear legitimate, and may already have partial information about your business before they dial. The goal is to sound so credible that the employee never thinks twice.

Cleveland Businesses Use the Same Tools ADT’s Employee Did

Here’s what should give every Cleveland area business owner pause: the tools that ADT’s employee used — Okta, Salesforce, Microsoft 365, Google Workspace, Slack — are the exact same platforms powering thousands of Northeast Ohio companies every day. From logistics firms near the port to law offices downtown to healthcare practices in the suburbs, these cloud platforms are the backbone of modern operations.

That’s precisely what makes this style of attack so dangerous. ShinyHunters didn’t need to hack ADT’s infrastructure. They hacked a person. And once they had SSO access, every connected SaaS application became fair game — Salesforce, Microsoft 365, Slack, Zendesk, Dropbox, and more.

A single successful vishing attempt can open the door to your entire digital environment.

Why Summer Makes Businesses More Vulnerable

The summer season creates unique security risk windows. Vacations leave experienced staff unavailable, temporary workers fill in without full security training, and the general hum of warm-weather business activity means phone calls get answered faster with less scrutiny. Attackers know this. Social engineering campaigns often surge during busy periods precisely because people are distracted and cover staff are less likely to question an urgent-sounding caller.

If your team is running leaner this June, July and August, it’s worth asking: would a temp or junior employee know how to respond if someone called claiming to be from IT and asking them to verify their login?

How to Protect Your Business from Vishing

Defending against vishing doesn’t require a massive budget — it requires consistent habits and the right policies in place:

  • Implement phishing-resistant MFA on all SSO accounts. Standard SMS-based MFA can be socially engineered; hardware keys or app-based authentication with number matching are far harder to bypass.
  • Train employees to verify callers before sharing any credentials or approving authentication prompts. A simple rule: if someone calls asking you to log in or approve something, hang up and call them back on a verified number.
  • Establish a clear escalation path so employees feel empowered to pause, question, and report suspicious calls without fear of slowing things down.
  • Limit SSO access scope. Not every employee needs access to every connected application. Least-privilege principles reduce the blast radius if an account is ever compromised.
  • Run regular security awareness training, especially before high-risk periods like summer, when staffing fluctuates and attackers look for openings.

How Accellis Can Help

We work with Cleveland-area businesses to build security programs that account for the human element — because technology alone isn’t enough. From security awareness training that teaches your team to recognize and respond to a vishing attack, to identity and access management reviews that close the gaps attackers exploit, we help you stay ahead of the threats that don’t make headlines until it’s too late.

Don’t wait for a breach to find out where your gaps are. Contact us today and let’s make sure your business doesn’t become the next case study.

Discover how Accellis can enhance your organization's efficiency and productivity.