ReliaQuest: the confirmed attack that didn't go further
On August 22, 2026, cybersecurity firm ReliaQuest confirmed it
was targeted by a social engineering attack: vishing, a fake login page, one
employee tricked. Unlike most case files in this Laboratory, this one
documents an attack that worked up to a point, then was stopped
— and explains precisely why.
✅ Confirmed by the company itself, on the
essentials. ReliaQuest has publicly acknowledged the attack and its
mechanism. The disagreement is only about scale: ShinyHunters claims a breach,
ReliaQuest confirms a temporary, limited exposure, with no evidence of customer
data access to date.
The numbers, and what backs them
Aug 22
Date of the social engineering attack attempt, confirmed
by ReliaQuest.
ReliaQuest statement.
1
Employee who entered credentials and approved an MFA push
on the fake page — one is enough to open a session.
ReliaQuest, via The Register.
View only
Extent of the access obtained: a view-only look at an
internal identity dashboard, per ReliaQuest.
Official ReliaQuest statement.
0
Internal application or system reached; customer data
touched, per ReliaQuest.
Official ReliaQuest statement.
Timeline
CONFIRMED
August 22, 2026
Attackers call several ReliaQuest employees while
impersonating a named member of the security team, directing them to a
cloned single sign-on (SSO) page hosted on a lookalike domain.
CONFIRMED
August 22, 2026
One employee enters their password on the fake page and
approves an MFA push notification on their phone. Attackers obtain a valid
session on the company's identity dashboard.
CONFIRMED
August 22, 2026
Attackers attempt to pivot from that dashboard into
ReliaQuest's internal applications. The pivot fails: access controls require
a company-managed, recognized device, which the attackers don't have. The
security team terminates the session, expires the password, and resets
authentication factors.
CLAIMED
August 23, 2026
ShinyHunters posts a claim on its leak site, with
screenshots of the Okta dashboard that was accessed. No customer data, no
validated sample, and no documented ransom demand accompany the post.
🔐What stopped the attack, precisely
The password was compromised. MFA was bypassed — the employee approved the
push themselves. In many companies, that would have been enough. Here, one
additional control held: access to internal applications requires not just a
valid identity, but also a device recognized and managed by the
company. A stolen session from an attacker's personal device, even
with the right credentials, doesn't clear that second filter. That control —
not the password, not MFA alone — is what made the difference.
Source: official ReliaQuest statement, via SecurityWeek.
What this means for you
The mechanism that tricked this employee — a call posing as internal
security, a login page that looks exactly like the real one, an MFA approval
request framed as routine — is exactly the kind of manipulation Egidio is built
to intercept on the call and messaging side. The rule that protects stays the
same, at work or at home: no legitimate security team ever asks you to approve
an authentication push over the phone. See also
Emerging phishing
techniques.
🔒 If a call asks you to approve an authentication
notification while you're on the line with the caller, hang up and verify
through an independent channel — even if the caller ID looks legitimate.
Frequently asked questions
Was ReliaQuest customer data stolen?
No, per ReliaQuest: no applications or customer data were reached, access
was limited to viewing an internal dashboard.
Why didn't the attack go further despite a compromised password and MFA?
A device-trust control blocked the pivot to internal applications — that
filter, not MFA alone, stopped the attack.
Did ShinyHunters provide proof of the hack?
Dashboard screenshots, but no customer data or validated sample to
date.
📌 Last checked: August 25, 2026.
Verifiable information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "ReliaQuest: the confirmed attack that didn't go further," egidio.app/en/laboratoire/reliaquest-attack-blocked-shinyhunters/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.