ReliaQuest Employee Tricked Into Okta SSO Login

Help Net Security · Medium sophistication
Last updated August 25, 2026

ReliaQuest confirmed an employee was socially engineered into entering their password on a fake SSO page and approving an MFA push, giving attackers a brief “view only” session in the company’s identity dashboard. The attackers allegedly impersonated a named member of the security team over the phone and guided staff to a lookalike login site. ReliaQuest says controls prevented access to business apps or customer data, and the session was terminated quickly.

Key findings

  • ReliaQuest confirmed an employee provided a password and approved an MFA push after being guided to a fake SSO page.
  • Attackers used a lookalike domain and a fake SSO page “hiding it behind a content delivery network.”
  • The phone-based pretext involved impersonating “a named member of the security team.”
  • ReliaQuest states attacker access was “view only,” and controls blocked access to applications and customer data.
  • Response actions included terminating the session, forcing a password reset, and resetting authentication factors tied to the account.
  • The wider campaign referenced registration of domains using company names under the “.claims” TLD and impersonation of “legal teams, help desks, and IT staff.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk/service desk, Security team, Finance (general high-risk role for impersonation/BEC-style follow-on), Executives.
  • Affected industries: Cybersecurity services, Technology / IT services.
  • Attack channels: vishing, website.
  • Impersonated: ReliaQuest security team (named member).

Awareness takeaways

  • Treat unexpected calls about security issues as suspicious; verify the caller via a known internal directory or ticketing system before taking action.
  • Never approve an MFA push you didn’t initiate; report it immediately as a likely account-takeover attempt.
  • Be cautious of lookalike domains and login pages; use bookmarked/known SSO URLs rather than ones provided over the phone.
  • Assume credential theft can happen and limit blast radius with strong access controls and rapid response (terminate sessions, reset factors).

Red flags to watch for

  • Unexpected phone call urging you to log in via a link/page the caller provides
  • Lookalike domain / nonstandard login URL for SSO
  • Unsolicited MFA push prompt you did not initiate
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

ReliaQuest just had this: a caller says, “I’m from security,” and walks an employee straight into a fake Okta SSO login. The impostor used a lookalike domain, hid it behind a content delivery network, and coached them to type their password and tap “Approve” on an MFA push. That one tap gave a brief, view-only session into their identity dashboard. The same campaign used company-name '.claims' domains and pretended to be legal, help desk, even IT staff over the phone. Here’s your move: if anyone calls about a “security issue” and tells you where to log in or to approve an MFA push, hang up and call them back using our internal directory before you touch anything.

Similar attacks

ShinyHunters Hit ReliaQuest With SSO Phish + Calls

ShinyHunters Hit ReliaQuest With SSO Phish + Calls

ReliaQuest said it was targeted in a ShinyHunters-linked social engineering attack that used a fake domain hosting a ReliaQuest single sign-on (SSO) phishing page. Attackers then called employees while impersonating named security staff to push victims to the fake login page, resulting in one…

August 24, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ReliaQuest disclosed a real social engineering incident where attackers registered a lookalike domain, hosted a fake ReliaQuest SSO page, and called employees while impersonating a named security employee. One employee entered credentials and approved an MFA push, briefly giving the attacker…

August 25, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
AI “Apple Support” Calls Steal Passcodes & 2FA

AI “Apple Support” Calls Steal Passcodes & 2FA

Researchers uncovered a phishing-as-a-service platform (“AnonyMousKIT”) used by phone thieves to trick victims into handing over iPhone passcodes, Apple ID passwords, and live 2FA codes so thieves can remove Apple’s Activation Lock. The operation uses Apple-branded emails/pages and AI voice agents…

August 26, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026