Hackers Impersonate ReliaQuest Security Staff to Steal SSO Credentials and MFA Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

ReliaQuest has disclosed a social engineering attack in which threat actors impersonated members of its security team to lure employees to a fraudulent single sign-on page.

The incident briefly exposed one employee identity, but ReliaQuest said its layered controls prevented access to internal applications, customer data, and business systems. The attack occurred on August 22, 2026, and used a targeted voice-phishing (vishing) approach.

The attackers registered a lookalike ReliaQuest domain and hosted a counterfeit SSO portal behind a content delivery network. This infrastructure was designed to appear legitimate while masking the phishing site’s underlying hosting environment.

The threat actors then called multiple ReliaQuest employees, posing as named security staff members. Their objective was to persuade targets to visit the malicious login page and authenticate.

Hackers Impersonate to Steal SSO Credentials

One employee entered their password and accepted an MFA push notification on their phone, allowing the attackers to obtain a temporary session for ReliaQuest’s identity dashboard.

ReliaQuest said the compromised session had view-only access. The company stated that no internal applications or systems were accessed, no customer data was exposed, and the attackers could not move beyond the identity dashboard.

Existing security controls blocked attempts to access additional applications. According to the company, device-trust controls played a central role in containing the incident.

Those controls prevent unmanaged or non-ReliaQuest devices from accessing applications and systems, meaning possession of a valid identity session alone did not provide the attacker with broad access.

ReliaQuest also terminated the attacker’s sessions, expired the affected password, and reset all authentication factors linked to the employee account.

A subsequent investigation reviewed control operation, device trust, on-network access, and suspicious activity during the prior 48 hours.

ReliaQuest concluded that only one identity session was exposed and that no other identities, business applications, or company and customer data were accessed.

The company also found no evidence of persistence. It rejected claims that it had suffered a ransomware attack or broader compromise. The incident reflects a growing pattern of identity-focused intrusions across enterprise environments.

Attackers increasingly combine employee impersonation, newly registered lookalike domains, phishing pages hosted behind CDN infrastructure, MFA push abuse, and rapid attempts to enroll attacker-controlled authenticators.

Canadian cybersecurity authorities have warned that such actors often impersonate internal IT personnel or trusted vendors and direct victims to attacker-controlled authentication portals.

The case demonstrates why MFA alone is not always sufficient against real-time social engineering. A user who enters credentials and approves a malicious prompt can still hand over an active session.

Organizations can reduce this risk by adopting phishing-resistant authentication methods such as FIDO2 or WebAuthn security keys, restricting access from unmanaged devices, monitoring unusual session behavior, and requiring stronger verification before MFA resets or new authenticator enrollment.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Impersonate ReliaQuest Security Staff to Steal SSO Credentials and MFA Access appeared first on Cyber Security News.