VYPR
advisoryPublished Aug 24, 2026· Updated Aug 25, 2026· 4 sources

ReliaQuest Thwarts Vishing Attack Impersonating Security Staff to Steal SSO Credentials

ReliaQuest has successfully defended against a sophisticated vishing attack where threat actors impersonated its own security team to steal employee credentials and MFA access.

ReliaQuest has disclosed a targeted social engineering attack that occurred on August 22, 2026, where malicious actors impersonated members of the company's security team. The attackers employed a voice-phishing (vishing) strategy, registering a domain that closely mimicked ReliaQuest's legitimate web presence and setting up a counterfeit single sign-on (SSO) portal hosted behind a content delivery network. This elaborate setup was designed to deceive employees into believing they were interacting with official ReliaQuest resources.

The threat actors initiated contact by calling multiple ReliaQuest employees, falsely claiming to be security staff. Their objective was to coerce these employees into visiting the fraudulent SSO page and authenticating their credentials. This impersonation tactic aimed to leverage the trust employees place in their internal security teams to bypass standard security awareness.

One employee fell victim to the scheme, entering their username and password into the fake portal. Critically, the attacker also managed to obtain an MFA push notification approval on the employee's device. This allowed the threat actors to gain temporary, view-only access to ReliaQuest's identity dashboard. However, this access was severely limited by the company's robust security architecture.

ReliaQuest emphasized that its layered security controls, particularly device-trust mechanisms, effectively prevented the attackers from escalating their access. These controls ensure that only authorized and managed devices can access internal applications and sensitive data. Consequently, the compromised session, despite having valid credentials and MFA approval, could not be used to access any internal applications, customer data, or critical business systems beyond the limited scope of the identity dashboard.

Following the incident, ReliaQuest took immediate action to contain the breach. The attacker's sessions were terminated, the compromised password was expired, and all authentication factors associated with the affected employee account were reset. A thorough investigation was launched, examining control operations, device trust logs, network access records, and any suspicious activity within the preceding 48 hours.

The investigation concluded that only a single identity session was compromised and that there was no evidence of persistence, broader compromise, or unauthorized access to any customer data or internal systems. ReliaQuest explicitly refuted any claims of a ransomware attack or a significant data breach, highlighting the efficacy of their security posture.

This incident underscores a broader trend in sophisticated cyberattacks that focus on identity compromise. Attackers are increasingly combining social engineering tactics, such as impersonation and MFA push abuse, with technical methods like lookalike domains and CDN-hosted phishing pages. The case serves as a stark reminder that while MFA is a crucial security layer, it is not infallible against well-executed real-time social engineering attacks, especially when users are tricked into approving malicious prompts.

To mitigate such risks, organizations are advised to implement phishing-resistant authentication methods like FIDO2 or WebAuthn security keys, enforce strict access controls for unmanaged devices, and enhance monitoring for unusual session behaviors. Prompt and thorough incident response, coupled with continuous security control validation, remains paramount in defending against these evolving threats.

The new article provides further details on the ShinyHunters campaign, confirming that the threat actor group was behind the attack on ReliaQuest. It elaborates on the social engineering tactics used, including impersonating security staff and registering fake domains to host phishing pages, and reiterates that while a brief session on the identity dashboard was achieved, no sensitive customer data or business applications were compromised.

ReliaQuest has publicly refuted claims of a significant compromise following a social engineering attack attributed to the ShinyHunters threat group. While acknowledging that an employee's credentials were briefly exposed via a phishing site, the company emphasized that their security platform remained unaffected and no customer data was accessed. The incident underscores ReliaQuest's defense-in-depth strategy, which includes robust controls to contain such breaches, even when initial phishing attempts are successful.

This new report details how the ShinyHunters group taunted ReliaQuest on X prior to the attack, with an account named @odysseusgroup posting "Who's hunting who?" after ReliaQuest's threat research team had warned about ShinyHunters' expanding social engineering tactics. ShinyHunters has also claimed a larger breach than ReliaQuest has admitted, posting screenshots on their leak site that appear to show access to a ReliaQuest Okta SSO account, while ReliaQuest maintains only a single identity was temporarily exposed and no customer data was accessed.

Synthesized by Vypr AI