ReliaQuest Warns of Phishing Attacks Impersonating Staff for SSO Credentials
Key Takeaways Threat actors impersonated ReliaQuest security staff in a sophisticated voice-phishing (vishing) attack. The attackers aimed to steal Single Sign-On (SSO) credentials from employees...
Key Takeaways
- Threat actors impersonated ReliaQuest security staff in a sophisticated voice-phishing (vishing) attack.
- The attackers aimed to steal Single Sign-On (SSO) credentials from employees using a fraudulent login page.
- One employee’s identity was briefly compromised, but ReliaQuest’s robust security controls prevented further access to internal systems or customer data.
- The incident highlights the evolving threat of identity-focused intrusions and the limitations of MFA against real-time social engineering.
ReliaQuest Thwarts Sophisticated Vishing Attack Targeting Employee SSO Credentials
ReliaQuest has revealed details of a targeted social engineering campaign where malicious actors posed as members of its internal security team. The sophisticated attack aimed to trick employees into divulging their Single Sign-On (SSO) credentials via a deceptive login portal.
Table Of Content
Although the incident, which occurred on August 22, 2026, resulted in the brief compromise of one employee’s identity, ReliaQuest’s multi-layered security framework successfully blocked any unauthorized access to its internal applications, sensitive customer data, or critical business systems. The attackers employed a highly targeted voice-phishing (vishing) strategy.
The perpetrators meticulously prepared their infrastructure, registering a domain visually similar to ReliaQuest’s official web presence. They subsequently hosted a convincing, yet fraudulent, SSO portal behind a content delivery network (CDN). This setup was designed to lend an air of legitimacy to the phishing site while simultaneously obscuring its true hosting environment.
Following the infrastructure setup, the threat actors initiated calls to multiple ReliaQuest employees. During these calls, they impersonated specific, named security personnel, attempting to convince their targets to navigate to the malicious login page and authenticate their credentials.
Hackers Impersonate to Steal SSO Credentials
One employee unfortunately fell victim to the ruse, entering their password and approving an MFA push notification on their mobile device. This action granted the attackers a temporary session to ReliaQuest’s identity dashboard.
ReliaQuest’s internal investigation confirmed that the compromised session was restricted to view-only access. The company explicitly stated that no internal applications or systems were breached, no customer data was exposed, and the attackers were unable to advance beyond the identity dashboard’s confines.
Existing security measures proved effective in thwarting attempts to access additional applications. ReliaQuest highlighted that its device-trust controls were instrumental in containing the incident, preventing any broader compromise.
These crucial controls are designed to block access to applications and systems from unmanaged or non-ReliaQuest devices. This meant that even with a valid identity session, the attackers could not gain extensive access to the company’s network.
In response to the breach, ReliaQuest promptly terminated the attacker’s sessions, invalidated the compromised password, and reset all authentication factors associated with the affected employee account.
A thorough post-incident review was conducted, examining the operation of security controls, device trust mechanisms, on-network access logs, and any suspicious activity recorded within the preceding 48 hours.
ReliaQuest concluded that only a single identity session was compromised, and there was no evidence of access to other identities, business applications, or any company or customer data.
Furthermore, the investigation found no indications of persistent access. ReliaQuest explicitly debunked any speculation regarding a ransomware attack or a more extensive system compromise. This incident underscores a growing trend of identity-focused intrusions observed across various enterprise environments.
Modern attackers are increasingly combining tactics such as employee impersonation, the registration of new lookalike domains, hosting phishing pages behind CDN infrastructure, abusing multi-factor authentication (MFA) push notifications, and rapidly attempting to enroll attacker-controlled authenticators.
Canadian cybersecurity authorities have previously cautioned organizations about threat actors frequently impersonating internal IT personnel or trusted third-party vendors, subsequently directing victims to attacker-controlled authentication portals.
This case serves as a critical reminder that MFA, while essential, may not always be sufficient against sophisticated real-time social engineering attacks. A user who inputs credentials and approves a malicious prompt can inadvertently hand over an active, legitimate session to attackers.
What You Should Do
- Implement phishing-resistant authentication methods such as FIDO2 or WebAuthn security keys to prevent session hijacking.
- Enforce strict device-trust policies, limiting access to corporate applications and systems exclusively to managed and authorized devices.
- Actively monitor for unusual session behavior, including logins from unfamiliar locations or devices, and flag rapid enrollment of new authenticators.
- Establish stringent verification procedures for MFA resets or the enrollment of new authentication factors to prevent attacker manipulation.
- Conduct regular security awareness training, emphasizing the dangers of social engineering, vishing, and the importance of verifying unexpected requests for credentials.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.