Egidio
Case file · August 25, 2026

ReliaQuest: the confirmed attack that didn't go further

On August 22, 2026, cybersecurity firm ReliaQuest confirmed it was targeted by a social engineering attack: vishing, a fake login page, one employee tricked. Unlike most case files in this Laboratory, this one documents an attack that worked up to a point, then was stopped — and explains precisely why.

Confirmed by the company itself, on the essentials. ReliaQuest has publicly acknowledged the attack and its mechanism. The disagreement is only about scale: ShinyHunters claims a breach, ReliaQuest confirms a temporary, limited exposure, with no evidence of customer data access to date.

The numbers, and what backs them

Aug 22
Date of the social engineering attack attempt, confirmed by ReliaQuest.
ReliaQuest statement.
1
Employee who entered credentials and approved an MFA push on the fake page — one is enough to open a session.
ReliaQuest, via The Register.
View only
Extent of the access obtained: a view-only look at an internal identity dashboard, per ReliaQuest.
Official ReliaQuest statement.
0
Internal application or system reached; customer data touched, per ReliaQuest.
Official ReliaQuest statement.

Timeline

CONFIRMED
August 22, 2026
Attackers call several ReliaQuest employees while impersonating a named member of the security team, directing them to a cloned single sign-on (SSO) page hosted on a lookalike domain.
CONFIRMED
August 22, 2026
One employee enters their password on the fake page and approves an MFA push notification on their phone. Attackers obtain a valid session on the company's identity dashboard.
CONFIRMED
August 22, 2026
Attackers attempt to pivot from that dashboard into ReliaQuest's internal applications. The pivot fails: access controls require a company-managed, recognized device, which the attackers don't have. The security team terminates the session, expires the password, and resets authentication factors.
CLAIMED
August 23, 2026
ShinyHunters posts a claim on its leak site, with screenshots of the Okta dashboard that was accessed. No customer data, no validated sample, and no documented ransom demand accompany the post.

🔐What stopped the attack, precisely

The password was compromised. MFA was bypassed — the employee approved the push themselves. In many companies, that would have been enough. Here, one additional control held: access to internal applications requires not just a valid identity, but also a device recognized and managed by the company. A stolen session from an attacker's personal device, even with the right credentials, doesn't clear that second filter. That control — not the password, not MFA alone — is what made the difference.

Source: official ReliaQuest statement, via SecurityWeek.

What this means for you

The mechanism that tricked this employee — a call posing as internal security, a login page that looks exactly like the real one, an MFA approval request framed as routine — is exactly the kind of manipulation Egidio is built to intercept on the call and messaging side. The rule that protects stays the same, at work or at home: no legitimate security team ever asks you to approve an authentication push over the phone. See also Emerging phishing techniques.

🔒 If a call asks you to approve an authentication notification while you're on the line with the caller, hang up and verify through an independent channel — even if the caller ID looks legitimate.

Frequently asked questions

Was ReliaQuest customer data stolen?

No, per ReliaQuest: no applications or customer data were reached, access was limited to viewing an internal dashboard.

Why didn't the attack go further despite a compromised password and MFA?

A device-trust control blocked the pivot to internal applications — that filter, not MFA alone, stopped the attack.

Did ShinyHunters provide proof of the hack?

Dashboard screenshots, but no customer data or validated sample to date.

📌 Last checked: August 25, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "ReliaQuest: the confirmed attack that didn't go further," egidio.app/en/laboratoire/reliaquest-attack-blocked-shinyhunters/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.