The recent ReliaQuest phishing attack highlights the persistent threat of social engineering targeting single sign-on credentials and multi-factor authentication. In August 2026, attackers impersonated ReliaQuest security staff to steal SSO credentials and abuse MFA, showing how layered defences can prevent wider compromise.
ReliaQuest Phishing Attack: What Happened
On 22 August 2026, ReliaQuest, a managed security provider, disclosed a sophisticated social engineering attack that targeted its employees. Threat actors registered a deceptive domain closely resembling the legitimate ReliaQuest website. Using this lookalike domain, they hosted a counterfeit single sign-on (SSO) portal behind a content delivery network (CDN), making the phishing site appear legitimate and masking its true location.
Attackers initiated a vishing campaign, calling several ReliaQuest employees and posing as members of the internal security team. During these calls, they urged employees to visit the fake SSO login page and authenticate using their corporate credentials.
- The attack began on 22 August 2026.
- Threat actors used a lookalike domain and CDN to host a convincing fake SSO portal.
- Vishing calls impersonated named ReliaQuest security staff.
- The goal was to capture employee credentials and MFA approvals.
One employee entered their password and accepted an MFA push notification on their phone, granting attackers a temporary, valid session for ReliaQuest’s identity dashboard. This allowed the attackers to access a view-only session but did not compromise internal applications, customer data, or business systems.
Technical Breakdown: Methods and Controls
The attackers’ approach combined several advanced social engineering techniques:
- Lookalike domain registration: A domain mimicking ReliaQuest was created to fool employees.
- Fake SSO portal: Hosted behind a CDN for authenticity and to conceal the real hosting infrastructure.
- Vishing (voice phishing): Attackers called employees, impersonating trusted security staff to increase credibility.
- MFA push abuse: Attackers prompted the victim to approve an MFA notification in real time, enabling session hijack.
ReliaQuest’s layered security controls played a crucial role in containing the incident:
- Device trust policies: Only managed, company-issued devices can access sensitive applications. Stolen credentials alone do not grant access without a trusted device.
- Session monitoring: The security team detected and terminated the attacker’s session promptly.
- Password and MFA reset: The affected account’s credentials and authentication factors were immediately reset.
- Post-incident review: A 48-hour retrospective analysis confirmed no additional compromise or persistence.
Despite the attackers gaining a session token for a single identity dashboard, their access was strictly limited. Existing policies blocked attempts to use that session for further lateral movement. No customer information, business applications, or sensitive systems were accessed. ReliaQuest’s findings confirmed that only one read-only session was exposed, with no broader impact.
Attack Timeline and Exploitation Status
- August 22, 2026: Attackers launch vishing calls using a lookalike ReliaQuest domain and fake SSO portal.
- One employee is tricked into entering credentials and accepting an MFA push, exposing a temporary session.
- ReliaQuest’s controls detect and block further unauthorised activity. The attacker’s session is terminated and credentials are reset.
- Post-incident investigation finds no evidence of further compromise, persistence, or access to customer data.
The incident is now contained. There is no evidence of ongoing exploitation, and ReliaQuest has denied any ransomware or broader compromise. The attack reflects an increasing trend of threat actors targeting corporate identities by combining social engineering with technical evasion, such as using CDN-hosted phishing portals and real-time MFA abuse.
Lessons from the ReliaQuest SSO and MFA Attack
Why this Attack Matters
This event underscores the continued evolution of phishing and social engineering techniques. Attackers are increasingly bypassing traditional MFA by tricking users into approving malicious prompts. Device trust and session monitoring can limit exposure, but phishing-resistant authentication methods are crucial to prevent session hijacking.
Actions for Organisations
- Adopt phishing-resistant authentication methods, such as FIDO2 or WebAuthn security keys, to prevent real-time phishing and MFA abuse.
- Enforce device trust policies, so only managed devices can access business-critical applications even if credentials are stolen.
- Monitor for unusual session activity and be prepared to respond quickly to identity-based attacks.
Originally reported by cybersecuritynews.com.





