ReliaQuest Reports Targeted Social Engineering Attack
In a recent incident, cybersecurity firm ReliaQuest disclosed the occurrence of a targeted social engineering attack that utilized sophisticated tactics to compromise an employee’s credentials. The attackers impersonated company security personnel and cleverly employed a spoofed domain to trick their victim into approving a malicious multi-factor authentication (MFA) request.
The attack was detected on August 22, 2026, and resulted in the temporary exposure of a single identity session that granted view-only access to ReliaQuest’s identity dashboard. Thankfully, the company’s robust security measures managed to thwart any further access to sensitive business applications, customer environments, or internal systems.
ReliaQuest has long been committed to sharing threat research materials through its Resource Center and various blog channels. Following the incident, the company provided insights into the nature of the attack, revealing that the campaign initiated with the registration of a deceptive domain that bore a striking resemblance to its legitimate web presence. This careful imitation is a known tactic employed by cybercriminals to confuse targets.
The attackers then devised a fake ReliaQuest single sign-on (SSO) portal using a content delivery network (CDN). This approach not only enhances the resilience of phishing infrastructure, making it less suspicious, but also allows for streamlined delivery of malicious content. Subsequent to the setup of the bogus portal, the threat actors exploited phone-based social engineering techniques, specifically vishing, to contact multiple employees.
During these calls, the attackers impersonated specific members of ReliaQuest’s security team. They instructively guided employees to authenticate themselves via the fraudulent SSO page. One unsuspecting employee complied, entering their password into the counterfeit portal and subsequently approving a malicious MFA notification that had pinged their mobile device. This action granted the attackers a short-lived session within the organization’s identity management environment, albeit limited to view-only access.
According to the information provided by ReliaQuest, the compromised session merely had view-only capabilities on its identity dashboard. Although attackers attempted to exploit this access to reach further applications, they were swiftly thwarted by the company’s stringent security controls. The organization’s defense-in-depth model played a crucial role in mitigating the potential damage, as it includes device-trust controls designed to prevent unmanaged or non-corporate devices from gaining access to enterprise applications and systems.
In light of the incident, quick and decisive incident response actions were undertaken. The malicious session was effectively terminated, the affected password was expired, and all authentication factors linked to the identity were reset. Following these immediate actions, a thorough investigation commenced, examining device-trust enforcement, on-network access, identity logs, and any suspicious activity that occurred in the preceding 48 hours.
Remarkably, ReliaQuest reported no evidence indicating additional compromised identities, nor did they find any established persistence mechanisms on the attackers’ part. Furthermore, there was no indication that customer or company data had been accessed, apart from the exposed login credentials themselves. The firm also categorically denied any allegations suggesting that it had experienced a ransomware incident or a more extensive compromise.
The incident serves as a stark reminder of prevalent identity-focused intrusion patterns. These attacks commonly involve the rapid registration of lookalike domains, phishing content delivered via CDN-backed infrastructure, employee impersonation, password harvesting, MFA prompt approvals, and the enrolling of new authenticators. Experts caution that relying solely on MFA does not render an organization immune to such attacks, particularly when individuals can be manipulated into approving notifications.
Organizations are advised to augment MFA with more resilient authentication methods, such as FIDO2 security keys or passkeys. They should enforce device posture checks, restrict authenticator enrollment procedures, and diligently monitor identity provider sessions for any anomalous activity.
Moreover, security teams are encouraged to treat unsolicited calls from IT or security personnel with skepticism, considering them as signals for verification events. Employees should independently confirm any requests through trusted internal channels, rather than acquiescing to instructions given on a call or approaching a login page provided by a caller.
As cyber threats continue to evolve, the imperative remains for organizations to fortify their defenses against increasingly sophisticated social engineering tactics. By fostering a culture of vigilance and education among employees, companies can better protect themselves from similar incidents in the future.

