ReliaQuest Discloses Failed Social Engineering Attack That Briefly Exposed One Identity

Summary
A caller impersonating a ReliaQuest security employee directed a teammate to a fake SSO page. The attacker briefly gained view-only access to one identity dashboard session; no applications or customer data were accessed.
Key points
- The attacker used a lookalike domain hosting a fake ReliaQuest SSO page behind a content delivery network.
- Callers impersonated ReliaQuest security staff and persuaded one teammate to enter a password and approve an MFA push.
- The attacker obtained a brief, view-only session on ReliaQuest’s identity dashboard.
- Device-trust controls blocked access to business applications and systems; ReliaQuest says no customer or company data was accessed beyond the user's login credentials.
- ReliaQuest terminated the sessions, expired the password, and reset all authentication factors; its investigation found no other identities accessed or persistence established.
- ReliaQuest said claims that it was compromised or targeted by ransomware are false.
Article Details
- Victim Organization
- ReliaQuest
- Incident Type
- Voice phishing and credential harvesting through a fake SSO page, followed by unauthorized identity-dashboard access
- Incident Date
- 2026-08-22
- Data Types Exposed
- One teammate's login credentials
- Affected Records
- One identity
- Operational Impact
- The attacker briefly obtained view-only access to the identity dashboard. ReliaQuest terminated the session, expired the password, and reset the authentication factors. Its investigation found no access to business applications or systems, no customer data access, and no persistence.
- Ransom Or Extortion
- ReliaQuest stated that claims it was targeted by ransomware were false. No ransom or extortion activity was reported.
- Claim Status
- confirmed
MITRE ATT&CK
T1078 · Valid AccountsThe attacker used a teammate's captured credentials and approved push notification to obtain a brief identity-dashboard session.T1566.004 · Spearphishing VoiceThe attacker called teammates while impersonating a named security employee and directed them toward a fake SSO page.T1621 · Multi-Factor Authentication Request GenerationThe attack involved MFA push abuse; one teammate approved a push notification.