My phone rang from a number I didn't know. The person on the other end talked to me like we'd been at university together, then invited me to a cybersecurity conference with a speaker list full of CEOs and big names. I never registered for it. I'd never heard of it. They still had my mobile number, my private email and my work email, and they read the addresses back to me as if that should make me feel welcome. The conference is real. That is exactly why it bothers me.
This isn't a scam story. I checked, the event exists, the speakers are real people, and nobody asked me for a card number. I'm not naming the organiser, because the point isn't one company. It's a pattern that the security industry should be the first to kill, and instead it's running it.
If a security conference calls you the way an attacker would, it's training you to say yes to attackers.
Why a legit event makes it worse, not better
Look at the call as a social engineer would. A warm, overfamiliar opening so you drop your guard. Name-dropping (big speakers, important people) to borrow authority. Proof that they already know you: three contact details, one of them private. Then a soft deadline: limited seats, decide now.
That's the pretexting playbook, step by step. Every awareness training I've seen tells people to slow down exactly when a stranger knows too much and wants a quick yes.
Scams get reported, blocked and laughed about in the team chat. A legit event that does the same thing gets a polite "send me the details". Do that a few times and the pattern starts to feel normal. The next caller who knows your private email and mentions a famous name gets the same polite answer, and that one might not be selling conference tickets.
An organiser who works in security knows all of this. Which is what irritates me most.
Where they probably got my data
I don't know the exact source, and that's part of the complaint. But I can guess the usual supply chain, because I've seen it from the vendor side:
- B2B enrichment tools. Apollo, ZoomInfo, Lusha, Cognism and similar services sell work emails and direct dials, often guessed from email patterns or collected through browser extensions that read users' contact lists.
- Scraped profiles. LinkedIn data scraped at scale and resold, matched with phone numbers from other sources.
- Old attendee lists. If you once went to an event or downloaded a whitepaper, that list can travel further than you'd think, sometimes through "partner" sharing nobody reads.
- Breach data. Plenty of "enriched" records trace back to leaks. Check your addresses on Have I Been Pwned and you'll often find where the private email escaped.
The work email alone I could shrug off. The private email is the real red flag. Someone joined my personal identity to my work identity and put both in a sales list. That joined record is precisely what a targeted phishing campaign needs, and now it sits in some CRM with who knows what access controls.
What GDPR actually says about this
I'm not a lawyer and I'm not the regulator, so I'll say "likely breach" rather than "breach". But the rules here are not obscure.
- They need a legal basis. GDPR Article 6. For marketing that's usually consent or legitimate interest. Recital 47 allows legitimate interest for direct marketing, but it has to be balanced against what the person would reasonably expect. I didn't expect a stranger to have my private email.
- They must tell you where the data came from. Article 14 covers data not collected from you. If they use it to contact you, they owe you that information at the latest at the first communication, including the source (Art. 14(2)(f) and 14(3)(b)). The first communication was that call. Nobody mentioned a source.
- You can say no, and that's final. Article 21(2) and (3): object to direct marketing and they must stop processing your data for it. No balancing test.
- Calls have their own rules. The ePrivacy Directive Article 13 lets each country set its own rules for live marketing calls. I'm in Germany, where they are strict (next section).
Even the most generous reading for the organiser has a gap: they knew my data, used it to call me, and couldn't tell me how they got it. That alone is hard to defend.
In Germany, the phone call itself is the problem
German competition law treats cold calls as unreasonable harassment. § 7 Abs. 2 Nr. 1 UWG allows advertising calls to consumers only with prior express consent. Calls to businesses need at least presumed consent, meaning the caller had concrete reasons to believe you'd welcome this particular call. "He works in IT, he'll like a security conference" is the kind of argument German courts have rejected before.
Since October 2021, § 7a UWG also requires companies to document consumer consent for phone advertising and keep that record for five years. If they called your private mobile and can't show where you said yes, that's their problem, not yours. The Bundesnetzagentur enforces this and can fine up to €300,000 per violation (§ 20 UWG). It runs a complaint form for unwanted calls. Note the date, time, caller number and company name while you still remember them.
What to do when the call comes
On the call, keep it short and boring. Three questions:
1. What is your company's legal name?
2. Where did you get my phone number and email addresses?
3. Please note that I object to direct marketing under GDPR Article 21.
Don't confirm anything they don't already have. Don't "verify" your email. Don't click the link they promise to send, and if you're interested in the event after all, find it yourself through a search engine and register through the official site.
After the call, send a written access request. Plain email to their privacy contact is enough:
Subject: Data subject access request (GDPR Art. 15) and objection (Art. 21)
You contacted me by phone on [date] about [event].
Please provide, within one month (Art. 12(3)):
- all personal data you hold about me
- the source of each item (Art. 15(1)(g))
- the legal basis and purposes of processing
- every recipient you have shared it with
I object to processing of my personal data for direct marketing
(Art. 21(2)) and request erasure (Art. 17).
The answer to "source" is the useful part. If it names a data broker, send that broker the same letter. That's how you actually get out of the list, instead of out of one company's copy of it.
If they ignore you after a month, or can't name a source, file a complaint with a data protection authority. In Germany that's the state authority (Landesdatenschutzbehörde) where the company is based. Elsewhere in the EU, the EDPB keeps the list. The cold call itself goes to the Bundesnetzagentur. Two complaints, maybe forty minutes in total, and it's the only feedback these teams notice.
Tell your security team too
Because my work email was on that list, this isn't only my problem. A record that links a named employee's work address, private address and mobile is a ready-made target for spear phishing, MFA fatigue attacks and fake IT helpdesk calls. Your security team wants to know when a list like that is circulating, even if the first caller was harmless.
Forward them a short note: date, caller number, what they knew, what they claimed to be. If three colleagues report the same caller in a week, that's signal.
What organisers should do instead
Security events have the easiest audience in the world to reach honestly. Post on LinkedIn. Work with communities and meetups. Let people opt in. If you must do outbound, send one email to a work address, say where you got it, and include an unsubscribe link that works.
Every security conference has at least one talk about social engineering. Somebody on the sales team should go to it.