ReliaQuest Hit by Vishing + Fake SSO MFA Push Scam

The Hacker News · Medium sophistication
Last updated August 27, 2026

ReliaQuest reported a real social-engineering incident where an attacker impersonated a security team member, called employees, and directed them to a fake ReliaQuest SSO login page hosted behind a CDN. One employee entered credentials and approved an MFA push, briefly giving the attacker view-only access to an identity dashboard. ReliaQuest says no customer data was accessed and the attacker’s access was limited.

Key findings

  • An attacker registered a lookalike domain and hosted a fake ReliaQuest SSO page behind a content delivery network (CDN).
  • The attacker called multiple employees while impersonating a named security team member to push them to the fake SSO page.
  • One employee entered their password and approved an MFA push notification, enabling brief session access to an identity dashboard (view-only).
  • ReliaQuest says no applications/systems were accessed and no customer data was touched.
  • ReliaQuest noted the playbook aligns with tactics used by ShinyHunters and other extortion crews, including lookalike domains, MFA push abuse, and rapid new authenticator enrollment attempts.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security, Finance, Executives.
  • Affected industries: Cybersecurity services, Professional services.
  • Attack channels: vishing, website.
  • Impersonated: ReliaQuest security team (specific employee name).

Awareness takeaways

  • Treat unexpected security-related phone calls as suspicious and verify the caller using a known internal contact method (not the number they called from).
  • Never approve an MFA push you did not initiate; report it immediately as a likely account-takeover attempt.
  • Be alert for lookalike domains and fake SSO pages, attackers may register and burn domains quickly to avoid detection.
  • Watch for rapid follow-on actions after a successful login (like attempts to add a new authenticator), which can indicate an active takeover in progress.

Red flags to watch for

  • Unexpected phone call pressuring you to log in immediately
  • Login page is on a lookalike domain (not the normal company domain)
  • Unprompted MFA push notification request
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this call: “Hi, this is Alex from the security team. We need you to sign in to the ReliaQuest SSO page right now for an urgent issue.” That really happened at ReliaQuest. Someone registered a lookalike domain, put a fake ReliaQuest SSO page behind a CDN, then called employees, by name, to herd them to that site. One teammate typed their password and hit approve on an MFA push they didn’t start. That handed over a brief session on an identity dashboard, exactly the kind of move used by ShinyHunters and other extortion crews. Here’s your move: if you ever get an unexpected security call or random MFA push, hang up, hit deny, and contact the security team using a number or channel you already trust.

Similar attacks

ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest Employee Tricked Into Okta SSO Login

ReliaQuest confirmed an employee was socially engineered into entering their password on a fake SSO page and approving an MFA push, giving attackers a brief “view only” session in the company’s identity dashboard. The attackers allegedly impersonated a named member of the security team over the…

August 25, 2026
ShinyHunters Hit ReliaQuest With SSO Phish + Calls

ShinyHunters Hit ReliaQuest With SSO Phish + Calls

ReliaQuest said it was targeted in a ShinyHunters-linked social engineering attack that used a fake domain hosting a ReliaQuest single sign-on (SSO) phishing page. Attackers then called employees while impersonating named security staff to push victims to the fake login page, resulting in one…

August 24, 2026
ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ReliaQuest disclosed a real social engineering incident where attackers registered a lookalike domain, hosted a fake ReliaQuest SSO page, and called employees while impersonating a named security employee. One employee entered credentials and approved an MFA push, briefly giving the attacker…

August 25, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026