VYPR
advisoryPublished Aug 24, 2026· 1 source

ReliaQuest Thwarts Vishing Attack Impersonating Security Staff to Steal SSO Credentials

ReliaQuest has successfully defended against a sophisticated vishing attack where threat actors impersonated its own security team to steal employee credentials and MFA access.

ReliaQuest has disclosed a targeted social engineering attack that occurred on August 22, 2026, where malicious actors impersonated members of the company's security team. The attackers employed a voice-phishing (vishing) strategy, registering a domain that closely mimicked ReliaQuest's legitimate web presence and setting up a counterfeit single sign-on (SSO) portal hosted behind a content delivery network. This elaborate setup was designed to deceive employees into believing they were interacting with official ReliaQuest resources.

The threat actors initiated contact by calling multiple ReliaQuest employees, falsely claiming to be security staff. Their objective was to coerce these employees into visiting the fraudulent SSO page and authenticating their credentials. This impersonation tactic aimed to leverage the trust employees place in their internal security teams to bypass standard security awareness.

One employee fell victim to the scheme, entering their username and password into the fake portal. Critically, the attacker also managed to obtain an MFA push notification approval on the employee's device. This allowed the threat actors to gain temporary, view-only access to ReliaQuest's identity dashboard. However, this access was severely limited by the company's robust security architecture.

ReliaQuest emphasized that its layered security controls, particularly device-trust mechanisms, effectively prevented the attackers from escalating their access. These controls ensure that only authorized and managed devices can access internal applications and sensitive data. Consequently, the compromised session, despite having valid credentials and MFA approval, could not be used to access any internal applications, customer data, or critical business systems beyond the limited scope of the identity dashboard.

Following the incident, ReliaQuest took immediate action to contain the breach. The attacker's sessions were terminated, the compromised password was expired, and all authentication factors associated with the affected employee account were reset. A thorough investigation was launched, examining control operations, device trust logs, network access records, and any suspicious activity within the preceding 48 hours.

The investigation concluded that only a single identity session was compromised and that there was no evidence of persistence, broader compromise, or unauthorized access to any customer data or internal systems. ReliaQuest explicitly refuted any claims of a ransomware attack or a significant data breach, highlighting the efficacy of their security posture.

This incident underscores a broader trend in sophisticated cyberattacks that focus on identity compromise. Attackers are increasingly combining social engineering tactics, such as impersonation and MFA push abuse, with technical methods like lookalike domains and CDN-hosted phishing pages. The case serves as a stark reminder that while MFA is a crucial security layer, it is not infallible against well-executed real-time social engineering attacks, especially when users are tricked into approving malicious prompts.

To mitigate such risks, organizations are advised to implement phishing-resistant authentication methods like FIDO2 or WebAuthn security keys, enforce strict access controls for unmanaged devices, and enhance monitoring for unusual session behaviors. Prompt and thorough incident response, coupled with continuous security control validation, remains paramount in defending against these evolving threats.

Synthesized by Vypr AI