Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmed

Optimizely confirms data breach after vishing attack on employees

Optimizely · Technology · United States · February 11, 2026

What happened

Optimizely, a New York ad tech company with more than 10,000 customers, notified customers of a breach after threat actors contacted it on February 11, 2026 claiming system access. The company said attackers obtained basic business contact information, internal CRM records and limited back-office documents, and that no sensitive customer data beyond basic business details was compromised. Optimizely said the attackers could not escalate privileges, install software or create backdoors.

How the deception worked

Attackers phoned Optimizely employees while impersonating IT support and used a helpdesk pretext to manipulate them into disclosing their credentials and reading back multi-factor authentication codes. With a valid authenticated session, the intruders reached the company's CRM and internal document stores and pulled business contact records and back-office material. The access was constrained: Optimizely said the attackers were unable to raise privileges, deploy software, or establish persistence, so the incident ended as data theft plus extortion pressure rather than a deeper compromise.

AI involvement · Unknown

Optimizely did not state whether synthetic voice was used on the calls.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA plus a hard rule that IT never asks for codes by phone would have made the credential handover valueless.

Sources (1)

  1. Ad tech firm Optimizely confirms data breach after vishing attack
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.