My phone rang from a number I didn't know. The person on the other end talked to me like we'd been at university together, then invited me to a cybersecurity conference with a speaker list full of CEOs and big names. I never registered for it. I'd never heard of it. They still had my mobile number, my private email and my work email, and they read the addresses back to me as if that should make me feel welcome. The conference is real. That is exactly why it bothers me.

This isn't a scam story. I checked, the event exists, the speakers are real people, and nobody asked me for a card number. I'm not naming the organiser, because the point isn't one company. It's a pattern that the security industry should be the first to kill, and instead it's running it.

If a security conference calls you the way an attacker would, it's training you to say yes to attackers.

Why a legit event makes it worse, not better

Look at the call as a social engineer would. A warm, overfamiliar opening so you drop your guard. Name-dropping (big speakers, important people) to borrow authority. Proof that they already know you: three contact details, one of them private. Then a soft deadline: limited seats, decide now.

That's the pretexting playbook, step by step. Every awareness training I've seen tells people to slow down exactly when a stranger knows too much and wants a quick yes.

Scams get reported, blocked and laughed about in the team chat. A legit event that does the same thing gets a polite "send me the details". Do that a few times and the pattern starts to feel normal. The next caller who knows your private email and mentions a famous name gets the same polite answer, and that one might not be selling conference tickets.

An organiser who works in security knows all of this. Which is what irritates me most.

Where they probably got my data

I don't know the exact source, and that's part of the complaint. But I can guess the usual supply chain, because I've seen it from the vendor side:

The work email alone I could shrug off. The private email is the real red flag. Someone joined my personal identity to my work identity and put both in a sales list. That joined record is precisely what a targeted phishing campaign needs, and now it sits in some CRM with who knows what access controls.

What GDPR actually says about this

I'm not a lawyer and I'm not the regulator, so I'll say "likely breach" rather than "breach". But the rules here are not obscure.

Even the most generous reading for the organiser has a gap: they knew my data, used it to call me, and couldn't tell me how they got it. That alone is hard to defend.

In Germany, the phone call itself is the problem

German competition law treats cold calls as unreasonable harassment. § 7 Abs. 2 Nr. 1 UWG allows advertising calls to consumers only with prior express consent. Calls to businesses need at least presumed consent, meaning the caller had concrete reasons to believe you'd welcome this particular call. "He works in IT, he'll like a security conference" is the kind of argument German courts have rejected before.

Since October 2021, § 7a UWG also requires companies to document consumer consent for phone advertising and keep that record for five years. If they called your private mobile and can't show where you said yes, that's their problem, not yours. The Bundesnetzagentur enforces this and can fine up to €300,000 per violation (§ 20 UWG). It runs a complaint form for unwanted calls. Note the date, time, caller number and company name while you still remember them.

What to do when the call comes

On the call, keep it short and boring. Three questions:

1. What is your company's legal name?
2. Where did you get my phone number and email addresses?
3. Please note that I object to direct marketing under GDPR Article 21.

Don't confirm anything they don't already have. Don't "verify" your email. Don't click the link they promise to send, and if you're interested in the event after all, find it yourself through a search engine and register through the official site.

After the call, send a written access request. Plain email to their privacy contact is enough:

Subject: Data subject access request (GDPR Art. 15) and objection (Art. 21)

You contacted me by phone on [date] about [event].
Please provide, within one month (Art. 12(3)):
- all personal data you hold about me
- the source of each item (Art. 15(1)(g))
- the legal basis and purposes of processing
- every recipient you have shared it with

I object to processing of my personal data for direct marketing
(Art. 21(2)) and request erasure (Art. 17).

The answer to "source" is the useful part. If it names a data broker, send that broker the same letter. That's how you actually get out of the list, instead of out of one company's copy of it.

If they ignore you after a month, or can't name a source, file a complaint with a data protection authority. In Germany that's the state authority (Landesdatenschutzbehörde) where the company is based. Elsewhere in the EU, the EDPB keeps the list. The cold call itself goes to the Bundesnetzagentur. Two complaints, maybe forty minutes in total, and it's the only feedback these teams notice.

Tell your security team too

Because my work email was on that list, this isn't only my problem. A record that links a named employee's work address, private address and mobile is a ready-made target for spear phishing, MFA fatigue attacks and fake IT helpdesk calls. Your security team wants to know when a list like that is circulating, even if the first caller was harmless.

Forward them a short note: date, caller number, what they knew, what they claimed to be. If three colleagues report the same caller in a week, that's signal.

What organisers should do instead

Security events have the easiest audience in the world to reach honestly. Post on LinkedIn. Work with communities and meetups. Let people opt in. If you must do outbound, send one email to a work address, say where you got it, and include an unsubscribe link that works.

Every security conference has at least one talk about social engineering. Somebody on the sales team should go to it.