ReliaQuest Thwarts Targeted Social Engineering Attack with Defense-in-Depth Controls
On August 22, 2026, cybersecurity firm ReliaQuest detected a sophisticated social engineering attack in which threat actors impersonated the company’s security personnel to gain access to an employee’s credentials. The attackers registered a spoofed domain mimicking ReliaQuest’s legitimate infrastructure and deployed a fake single sign-on (SSO) portal hosted on a content delivery network (CDN) to evade detection.
Using phone-based vishing tactics, the attackers contacted multiple employees, posing as named members of ReliaQuest’s security team. They directed one employee to authenticate via the fraudulent SSO page, where the victim entered their password and approved a malicious multi-factor authentication (MFA) push notification. This granted the attackers a temporary, view-only session within ReliaQuest’s identity dashboard.
Despite the breach, the company’s security controls including device-trust policies that block unmanaged devices prevented further access to business applications, customer environments, or internal systems. Incident response measures terminated the session, reset the compromised credentials, and revoked all linked authentication factors.
A subsequent investigation found no evidence of additional compromised identities, persistence mechanisms, or unauthorized access to sensitive data. ReliaQuest also confirmed that the incident did not involve ransomware or a broader compromise.
The attack highlights a growing trend in identity-focused intrusions, where threat actors exploit MFA fatigue by tricking users into approving fraudulent prompts. While MFA remains a critical security layer, the incident underscores the need for phishing-resistant authentication methods, such as FIDO2 security keys, alongside continuous monitoring of identity provider sessions.
Source: https://gbhackers.com/hackers-impersonate-security-staff-to-steal-credentials-in-reliaquest/
ReliaQuest cybersecurity rating report: https://www.rankiteo.com/company/reliaquest
"id": "REL1787576460",
"linkid": "reliaquest",
"type": "Breach",
"date": "8/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'ReliaQuest',
'type': 'Cybersecurity Firm'}],
'attack_vector': ['Vishing', 'Phishing (Fake SSO Portal)'],
'date_detected': '2026-08-22',
'description': 'On August 22, 2026, cybersecurity firm ReliaQuest detected a '
'sophisticated social engineering attack in which threat '
'actors impersonated the company’s security personnel to gain '
'access to an employee’s credentials. The attackers registered '
'a spoofed domain mimicking ReliaQuest’s legitimate '
'infrastructure and deployed a fake single sign-on (SSO) '
'portal hosted on a content delivery network (CDN) to evade '
'detection. Using phone-based vishing tactics, the attackers '
'contacted multiple employees, posing as named members of '
'ReliaQuest’s security team. They directed one employee to '
'authenticate via the fraudulent SSO page, where the victim '
'entered their password and approved a malicious multi-factor '
'authentication (MFA) push notification. This granted the '
'attackers a temporary, view-only session within ReliaQuest’s '
'identity dashboard. Despite the breach, the company’s '
'security controls including device-trust policies that block '
'unmanaged devices prevented further access to business '
'applications, customer environments, or internal systems. '
'Incident response measures terminated the session, reset the '
'compromised credentials, and revoked all linked '
'authentication factors. A subsequent investigation found no '
'evidence of additional compromised identities, persistence '
'mechanisms, or unauthorized access to sensitive data. '
'ReliaQuest also confirmed that the incident did not involve '
'ransomware or a broader compromise.',
'investigation_status': 'Completed',
'lessons_learned': 'The attack highlights a growing trend in identity-focused '
'intrusions, where threat actors exploit MFA fatigue by '
'tricking users into approving fraudulent prompts. While '
'MFA remains a critical security layer, the incident '
'underscores the need for phishing-resistant '
'authentication methods, such as FIDO2 security keys, '
'alongside continuous monitoring of identity provider '
'sessions.',
'post_incident_analysis': {'corrective_actions': ['Terminated the session',
'Reset compromised '
'credentials',
'Revoked all linked '
'authentication factors'],
'root_causes': ['MFA Fatigue',
'Social Engineering (Vishing)']},
'recommendations': ['Implement phishing-resistant authentication methods '
'(e.g., FIDO2 security keys)',
'Continuous monitoring of identity provider sessions'],
'response': {'containment_measures': ['Terminated the session',
'Reset compromised credentials',
'Revoked all linked authentication '
'factors'],
'incident_response_plan_activated': True},
'title': 'ReliaQuest Thwarts Targeted Social Engineering Attack with '
'Defense-in-Depth Controls',
'type': 'Social Engineering',
'vulnerability_exploited': 'MFA Fatigue'}