Identity security firm Aura confirms the breach was due to a “targeted phone phishing attack” – and the hackers only needed one hour of access.