ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and successfully persuaded one employee to approve a malicious multi-factor authentication (MFA) request.
The incident, detected on August 22, 2026, resulted in the temporary exposure of a single identity session with view-only access to ReliaQuest’s identity dashboard.
Fortunately, the company stated that its security controls prevented the attackers from accessing business applications, customer environments, or internal systems.
ReliaQuest shares threat research materials through its Resource Center and blog channels.
ReliaQuest Social Engineering Attack
According to ReliaQuest, the campaign began with the registration of a deceptive domain that closely resembled the company’s legitimate web infrastructure.
The attackers set up a counterfeit ReliaQuest single sign-on (SSO) portal using a content delivery network (CDN). This technique makes phishing infrastructure more resilient and less suspicious.
The threat actors then conducted phone-based social engineering, known as vishing, targeting multiple employees. During the calls, the attackers impersonated named members of ReliaQuest’s security staff and directed employees to authenticate via a fraudulent SSO page.
One employee entered their password into the fake portal and approved a malicious MFA push notification sent to their mobile device, granting the attackers a short-lived session within the organization’s identity management environment.
ReliaQuest stated that the compromised session had only view-only access to its identity dashboard. Although the attackers attempted to use this access to reach additional applications, they were blocked by the company’s security controls.
The company credited its defense-in-depth model, which includes device-trust controls that prevent unmanaged or non-corporate devices from accessing enterprise applications and systems, for containing the incident. Incident-response actions terminated the malicious session, expired the affected password, and reset all authentication factors linked to the identity.
A subsequent investigation reviewed device-trust enforcement, on-network access, identity logs, control effectiveness, and any suspicious activity from the preceding 48 hours.
ReliaQuest reported no evidence of additional compromised identities, no established persistence mechanisms, and no access to customer or company data beyond the exposed login credentials.
The company also denied claims that it experienced a ransomware incident or a broader compromise.
This attack illustrates a common identity-focused intrusion pattern that includes quickly registering lookalike domains, delivering phishing content via CDN-backed infrastructure, impersonating employees, harvesting passwords, approving MFA prompts, and attempting to enroll a new authenticator.
MFA alone does not prevent attacks when users can be manipulated into approving prompts. Organizations should pair MFA with phishing-resistant authentication methods, such as FIDO2 security keys or passkeys, enforce device posture checks, restrict authenticator enrollment, and continuously monitor identity provider sessions for anomalous activity.
Security teams should also treat unexpected calls from IT or security personnel as verification events. Employees should independently confirm requests through trusted internal channels rather than following a caller’s instructions or navigating to a provided login page.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

