ReliaQuest Blocks MFA Phishing Attack After Employee Credentials Are Compromised
ReliaQuest has disclosed a targeted social-engineering attack in which threat actors combined a lookalike single sign-on (SSO) portal, telephone-based employee impersonation, and MFA push abuse to obtain temporary access to a single employee identity.
The incident, detected on August 22, 2026, did not result in access to customer data, business applications, or internal systems.
Although one employee entered credentials into a fraudulent authentication page and approved an unsolicited MFA notification, layered identity and device-security controls restricted the attackers and enabled rapid containment.
ReliaQuest Blocks MFA Phishing Attack
ReliaQuest said claims that the incident resulted in a ransomware compromise or broader corporate breach are false. The campaign began when threat actors registered a domain designed to resemble a legitimate ReliaQuest property.
The attackers subsequently deployed a counterfeit ReliaQuest SSO authentication page behind a content delivery network (CDN), a technique that can provide disposable infrastructure while making malicious phishing sites appear more credible and complicating efforts to identify their underlying hosting environment.
The threat actors then escalated the social-engineering component by calling multiple employees and impersonating members of ReliaQuest’s security team.
The callers reportedly used employee names and organizational terminology to increase credibility and persuade targets to interact with the fraudulent authentication infrastructure.
One employee ultimately submitted a password and approved an MFA push notification, allowing the attackers to obtain a short-lived session associated with the employee’s identity dashboard.
Despite successfully obtaining valid credentials and an MFA-approved session, the attackers were unable to move deeper into ReliaQuest’s environment.
The compromised session provided only view-level access, and attempts to use the dashboard to reach additional applications were consistently blocked.
ReliaQuest’s device-trust controls played a critical role in separating identity authentication from application authorization.
Because the attackers were operating from an unauthorized, non-corporate device, authentication alone did not provide access to protected business applications or internal systems.
Following detection, ReliaQuest terminated the malicious session, expired the affected employee’s password, and reset every authentication factor associated with the account.
The company subsequently conducted an extensive review of its security-control fidelity, device-trust enforcement, network activity, and suspicious events during the following 48 hours.
Investigators found no evidence that additional identities had been accessed or that attackers reached business applications, customer environments, or internal infrastructure.
The investigation also found no evidence of persistence. Threat actors did not establish a durable foothold through newly created accounts, authentication changes, malware, remote-access tools, or other mechanisms.
ReliaQuest stated that no customer or company data was accessed beyond the compromised user’s login credentials. The outcome demonstrates how multiple security layers can significantly reduce the impact of a successful phishing and MFA-manipulation attempt.
The campaign reflects an increasingly common enterprise intrusion pattern in which attackers combine technical phishing infrastructure with highly personalized social engineering.
Lookalike domains can be registered quickly and abandoned before defenders fully investigate them, while CDN-backed phishing pages can conceal infrastructure changes.
Telephone impersonation adds another layer of pressure by making fraudulent authentication requests appear to originate from trusted internal personnel.
The incident highlights why organizations should assume that individual employees may eventually be deceived. Enterprises should adopt phishing-resistant authentication where possible, enforce device posture and conditional-access policies, restrict identity-dashboard privileges, and monitor unusual MFA activity and new authenticator enrollments.
Employees should independently verify unexpected security calls and reject MFA prompts they did not initiate. ReliaQuest’s experience shows that strong device trust, segmented authorization, and rapid identity containment can transform a successful credential-theft event into a contained and ultimately unsuccessful intrusion.
No Comment! Be the first one.