ReliaQuest phishing call tricks employee into MFA approval
Attackers tricked one ReliaQuest employee into typing a password into a fake company login page and approving a fraudulent login request on their phone. The stolen access was limited to a view-only screen and did not reach customer data or company systems.
- Report priority
- Medium
How it works
Attackers registered a lookalike ReliaQuest web address, built a fake login page on it, then called employees pretending to be ReliaQuest security staff and told them to sign in through that fake page.
What to do
ReliaQuest says it shut down the compromised session, reset the employee's password, and reset all their login credentials. Readers should watch official ReliaQuest channels for any follow-up notice rather than act on unexpected calls claiming to be from ReliaQuest security.
Technical details
Attackers register a web address that looks almost identical to ReliaQuest's real one and build a copy of its login page on it. They call several employees, claiming to be ReliaQuest security staff, and tell them to log in through that page to verify their account. One employee enters their password on the fake page and then approves a login approval alert sent to their phone, handing the attackers a temporary session into ReliaQuest's identity system.
The attackers used a typosquatted domain fronted by a content delivery network to host a fake ReliaQuest single sign-on portal, then ran vishing calls impersonating named security staff to drive one employee to it. The employee submitted credentials and approved a push-based MFA prompt, yielding a short-lived, view-only session in ReliaQuest's identity provider dashboard. Device-trust controls blocked the session from reaching enterprise applications. ReliaQuest's response terminated the session, rotated the password, and reset all authentication factors; a 48-hour log review found no other compromised identities, no persistence, and no customer or company data access.