> Aura says a targeted voice phishing attack against one of its employees led to unauthorized access to about 900,000 records [...]
Employers are often surprised when I ask for less access, but I firmly believe no random employee should have personal data access like this. Ideally you'd want to require the customer to be in the loop to access their data as employee.