ReliaQuest reported a real social-engineering incident where an attacker impersonated a security team member, called employees, and directed them to a fake ReliaQuest SSO login page hosted behind a CDN. One employee entered credentials and approved an MFA push, briefly giving the attacker view-only access to an identity dashboard. ReliaQuest says no customer data was accessed and the attacker’s access was limited.
Key findings
- An attacker registered a lookalike domain and hosted a fake ReliaQuest SSO page behind a content delivery network (CDN).
- The attacker called multiple employees while impersonating a named security team member to push them to the fake SSO page.
- One employee entered their password and approved an MFA push notification, enabling brief session access to an identity dashboard (view-only).
- ReliaQuest says no applications/systems were accessed and no customer data was touched.
- ReliaQuest noted the playbook aligns with tactics used by ShinyHunters and other extortion crews, including lookalike domains, MFA push abuse, and rapid new authenticator enrollment attempts.
Who’s being targeted
- Commonly targeted roles: All employees, IT, Security, Finance, Executives.
- Affected industries: Cybersecurity services, Professional services.
- Attack channels: vishing, website.
- Impersonated: ReliaQuest security team (specific employee name).
Awareness takeaways
- Treat unexpected security-related phone calls as suspicious and verify the caller using a known internal contact method (not the number they called from).
- Never approve an MFA push you did not initiate; report it immediately as a likely account-takeover attempt.
- Be alert for lookalike domains and fake SSO pages, attackers may register and burn domains quickly to avoid detection.
- Watch for rapid follow-on actions after a successful login (like attempts to add a new authenticator), which can indicate an active takeover in progress.
Red flags to watch for
- Unexpected phone call pressuring you to log in immediately
- Login page is on a lookalike domain (not the normal company domain)
- Unprompted MFA push notification request
Read the video transcript
Imagine this call: “Hi, this is Alex from the security team. We need you to sign in to the ReliaQuest SSO page right now for an urgent issue.” That really happened at ReliaQuest. Someone registered a lookalike domain, put a fake ReliaQuest SSO page behind a CDN, then called employees, by name, to herd them to that site. One teammate typed their password and hit approve on an MFA push they didn’t start. That handed over a brief session on an identity dashboard, exactly the kind of move used by ShinyHunters and other extortion crews. Here’s your move: if you ever get an unexpected security call or random MFA push, hang up, hit deny, and contact the security team using a number or channel you already trust.