ReliaQuest Thwarts Social Engineering Attack Using Fake SSO and MFA Push Abuse
Brief
A targeted social-engineering attack that used a lookalike single sign-on portal, phone-based employee impersonation, and abuse of MFA push to gain temporary access to a single user identity.
The incident, documented by ReliaQuest and detected on August 22, 2026, did not result in access to customer data, business applications, or internal systems,
Although one employee entered credentials on a fraudulent page and approved a push notification, layered identity and device security controls limited the attacker’s access and enabled rapid containment.
ReliaQuest Thwarts Social Engineering Attack
ReliaQuest said claims that it suffered a ransomware compromise or broader breach are false. The operation began with the registration of a domain that resembled a legitimate ReliaQuest property.
