
ReliaQuest says it contained a social engineering attack that briefly gave a threat actor access to a single employee identity session but did not allow access to company applications, systems, or customer data.
The attacker was not identified in the company's report, although the ShinyHunters cybercrime group subsequently claimed a breach of ReliaQuest on its leak site.
The attack occurred on August 22, 2026, according to an incident analysis published the following day by ReliaQuest Threat Research. The cybersecurity company said its investigation found that the attackers combined voice-based social engineering, a lookalike domain, a cloned single sign-on page, and MFA push approval to obtain the temporary session.
According to ReliaQuest, the threat actor first registered a domain resembling one used by the company and hosted a fake ReliaQuest SSO page behind a content delivery network. The attackers then called several employees while impersonating a named member of ReliaQuest's security staff and attempted to direct them to the phishing page.
ReliaQuest is a cybersecurity company that provides security operations, threat detection, and managed detection and response services to enterprise customers. Its products and services are designed to aggregate security telemetry and help security teams detect and respond to threats across their environments.
One employee ultimately entered their password into the phishing page and approved an authentication push notification on their phone. This gave the attackers a valid session on ReliaQuest's identity dashboard, but the company says the resulting access was limited to viewing that interface.
The attackers then attempted to pivot from the identity dashboard into ReliaQuest applications. Those attempts were blocked because the company's access controls require trusted ReliaQuest-managed devices before identities can reach internal applications or systems.
ReliaQuest said its incident response measures terminated the attacker's active sessions, expired the compromised password, and reset all authentication factors associated with the affected account.
The subsequent investigation covered device-trust enforcement, network access, control effectiveness, and suspicious activity during the preceding 48 hours. ReliaQuest said it found no evidence that additional accounts were compromised, business applications were accessed, customer or corporate data was obtained beyond the employee's credentials, or persistence was established.
The company also explicitly rejected claims that it had suffered a broader compromise or ransomware attack.
ShinyHunters listed ReliaQuest, LLC on its leak site, claiming responsibility for the incident, but the material shown does not demonstrate that the group obtained the application or customer access disputed by ReliaQuest.

ReliaQuest said the attack closely resembles social engineering activity currently affecting other organizations. The playbook involves calling employees while impersonating trusted personnel, rapidly registering disposable lookalike domains, placing credential-harvesting pages behind CDNs, abusing MFA push notifications, and attempting to enroll attacker-controlled authentication methods immediately after gaining access.






Leave a Reply