ReliaQuest has revealed that attackers impersonated members of its own security team in a targeted attack on August 22, 2026, aiming to steal employee single sign-on (SSO) credentials and multi-factor authentication (MFA) access. The company says only one employee was tricked into providing both password and approving a malicious MFA push, allowing attackers temporary, view-only access to the identity dashboard. Critical internal systems, customer data, and applications remained untouched thanks to layered security controls. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-impersonate-reliaquest-security-staff/))
The attackers set up a lookalike ReliaQuest domain and hosted a fake SSO login page using content delivery network infrastructure to obscure its true hosting location. They then used voice phishing (vishing), calling ReliaQuest employees while posing as named security staff, urging them to authenticate via the fake portal. One employee complied, providing credentials and accepting an MFA prompt. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-impersonate-reliaquest-security-staff/))
How ReliaQuest Contained the Breach
ReliaQuest’s security safeguards, particularly device-trust policies, blocked any access attempts from unmanaged or non-company devices. Although the attacker gained a valid session for the identity dashboard, they could not reach any business applications, internal systems, or customer data. The compromised session was terminated, the employee’s password was reset, and all associated MFA tokens were revoked. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-impersonate-reliaquest-security-staff/))
A review of activity over the 48 hours before the incident found no signs of further identity exposures, persistence, or lateral movement. The company evaluated device trust, on-network access, and suspicious behavior to reassure that no broader compromise occurred. ReliaQuest also rejected rumors of a ransomware event or large-scale breach. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-impersonate-reliaquest-security-staff/))
Industry Implications & Best Practices
This form of attack—combining employee impersonation, domains mimicking trusted ones, phishing pages masked by CDNs, abusing MFA push prompts, and quickly enrolling attacker-controlled authenticators—is increasingly common in enterprise breaches. Canadian authorities have warned about similar techniques, where threat actors pose as trusted internal personnel and lead victims to fraudulent authentication pages. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-impersonate-reliaquest-security-staff/))
The incident underscores that standard MFA and credential policies may not be enough to stop real-time social engineering attacks. Even with correct credentials and an approved MFA push, attackers can gain a session. To counteract this risk, companies are advised to adopt phishing-resistant methods like FIDO2 or WebAuthn security keys, enforce strict controls over device trust, monitor for unusual session behaviors, and require stronger verification before handling MFA resets or new authenticator enrollments. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-impersonate-reliaquest-security-staff/))
ReliaQuest’s case serves as a real-world example of why identity security must be holistic: the credentials themselves aren’t the sole weak point, but how and where they’re used. As phishing tactics become more sophisticated, security teams need evolving guardrails. Lookalike domains, MFA push abuse, and vishing aren’t new—but they’re getting sharper. What to watch next: how organizations will standardize phishing-resistant authentication and whether regulators will push harder on minimum identity security standards.