Fake SSO + MFA Push Used in Real Breaches

eSecurity Planet · Medium sophistication
Last updated August 31, 2026

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page and an MFA prompt approval to gain limited access.

How the attack worked

Two separate incidents show how social engineering continues to bypass technical defenses even when multi-factor authentication is in place. In the ReliaQuest case, an employee was presented with a fake single sign-on (SSO) login page. After the employee entered credentials, the attacker triggered an MFA push request, and the employee approved it. This combination, credential theft followed by MFA approval, gave the attacker temporary, view-only access to a dashboard.

Separately, Apollo Global Management's cloud platforms were accessed through social engineering, resulting in the theft of sensitive personal information, including names, addresses, dates of birth, and Social Security numbers. The exact method used to gain access to Apollo's cloud environment was not detailed, but it fits a broader pattern of attackers targeting account access and cloud platforms rather than exploiting software vulnerabilities directly.

Why it succeeded

The ReliaQuest attempt succeeded at the initial step because the fake SSO page looked convincing enough that an employee entered real credentials, and because the follow-up MFA prompt was approved rather than questioned. This reflects a known weakness in push-based MFA: it depends on the user correctly identifying an unexpected authentication request as suspicious in the moment, which is not always intuitive under time pressure.

In the Apollo case, social engineering targeting cloud platform access again points to how attackers look for the human decision point, whether that's a help desk process, an account recovery flow, or a login request, rather than trying to break through technical barriers directly.

What limited the damage

At ReliaQuest, the impact was contained by controls that did not depend solely on the login step:

  • Device-trust controls restricted what the attacker could reach, keeping sensitive systems and customer information out of scope.
  • The compromised credentials were revoked quickly.
  • A follow-up check found no evidence of persistence.

This illustrates that stopping credential theft entirely is difficult, but limiting what a stolen credential can actually do is achievable through layered access controls.

What to watch for and how to build resistance

Defenders across all employee levels, help desk, IT, cloud administration, and security operations should treat the following as red flags:

  • An SSO login page that appears in an unexpected context or looks slightly different from normal
  • An MFA push notification the employee did not initiate
  • Login or access requests tied to account recovery that try to bypass normal verification

Recommended steps include strengthening help-desk and account-recovery verification procedures, applying device-trust and least-privilege principles to dashboards and cloud platforms, and training employees to pause and verify through a separate trusted channel before approving any unexpected MFA prompt. When credentials are suspected of being entered into a phishing page, revoking them immediately and checking for persistence, as ReliaQuest did, is an effective containment step.

Key findings

  • Apollo Global Management was breached via social engineering of cloud platforms, resulting in theft of sensitive personal information (including SSNs).
  • ReliaQuest reported a ShinyHunters phishing attempt where an employee entered credentials into a fake SSO page and approved an MFA request, giving the attacker temporary, view-only access.
  • ReliaQuest’s device-trust controls limited what the attacker could access; credentials were revoked and no persistence was found.

Who’s being targeted

  • Commonly targeted roles: All employees, Help desk / Service desk, IT, Security operations (SOC), Cloud administrators, Identity & Access Management (IAM).
  • Affected industries: Financial services, Cybersecurity / Managed security services.
  • Attack channels: email, website.
  • Impersonated: Company SSO / identity provider login page, Account recovery / support (unspecified in article).

Red flags to watch for

  • SSO page is fake (unexpected login page or suspicious URL)
  • Unexpected MFA prompt after entering credentials
  • Login request not initiated by the employee
  • Unusual or urgent access request tied to account recovery
  • Requests to bypass normal verification steps
  • Cloud access activity inconsistent with normal user behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in the ReliaQuest phishing attempt?

An employee entered credentials into a fake SSO page and approved an MFA request during a ShinyHunters attack, giving the attacker temporary, view-only dashboard access.

Why didn't the attacker get further access at ReliaQuest?

Device-trust controls blocked access to sensitive systems and customer information, and the credentials were revoked with no persistence found.

How was Apollo Global Management affected?

Attackers used social engineering to breach Apollo Global Management's cloud platforms and steal sensitive information including names, addresses, dates of birth, and Social Security numbers.

What should organizations do to reduce this kind of risk?

Strengthen help-desk and account-recovery verification, apply device-trust and least-privilege controls, and train employees to treat unexpected SSO logins and MFA prompts as high-risk signs of phishing.

Read the video transcript

An employee at ReliaQuest typed their password into a fake SSO page, tapped approve on MFA… and the attacker was in. This wasn’t theory. ShinyHunters used a fake company SSO site, then an MFA push, to get temporary, view-only dashboard access at ReliaQuest. Apollo Global Management was hit too, via social engineering of their cloud platforms, and attackers stole personal data, including Social Security numbers. Here’s the trap: you get an email, click a link, see a login page that looks just like our SSO, you sign in, and then, ding, an MFA prompt you weren’t expecting. That combo is the giveaway. If you didn’t start the login yourself, that page and that push are almost certainly phishing. Your move: if a login page or MFA push is unexpected, hit deny, close the page, and report it to security immediately so we can revoke any credentials and check for persistence.

Similar attacks

Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This…

July 28, 2026