Hackers Impersonate ReliaQuest Security Team Member to Steal SSO Credentials and MFA Access
Brief
ReliaQuest has disclosed a social engineering attack in which threat actors impersonated members of its security team to lure employees to a fraudulent single sign-on page .
The incident briefly exposed one employee identity, but ReliaQuest said its layered controls prevented access to internal applications, customer data, and business systems. The attack occurred on August 22, 2026, and used a targeted voice-phishing (vishing) approach .
The attackers registered a lookalike ReliaQuest domain and hosted a counterfeit SSO portal behind a content delivery network. This infrastructure was designed to appear legitimate while masking the phishing site’s underlying hosting environment.
The threat actors then called multiple ReliaQuest employees, posing as named security staff members. Their objective was to persuade targets to visit the malicious login page and authenticate.
