Identity security firm confirms breach was due to a “targeted phone phishing attack” – and the hackers only needed one hour of access.