ReliaQuest phishing call tricks employee into MFA approval

Published August 24, 2026

Attackers tricked one ReliaQuest employee into typing a password into a fake company login page and approving a fraudulent login request on their phone. The stolen access was limited to a view-only screen and did not reach customer data or company systems.

Report priority
Medium

How it works

Attackers registered a lookalike ReliaQuest web address, built a fake login page on it, then called employees pretending to be ReliaQuest security staff and told them to sign in through that fake page.

What to do

ReliaQuest says it shut down the compromised session, reset the employee's password, and reset all their login credentials. Readers should watch official ReliaQuest channels for any follow-up notice rather than act on unexpected calls claiming to be from ReliaQuest security.

Technical details

Attackers register a web address that looks almost identical to ReliaQuest's real one and build a copy of its login page on it. They call several employees, claiming to be ReliaQuest security staff, and tell them to log in through that page to verify their account. One employee enters their password on the fake page and then approves a login approval alert sent to their phone, handing the attackers a temporary session into ReliaQuest's identity system.

The attackers used a typosquatted domain fronted by a content delivery network to host a fake ReliaQuest single sign-on portal, then ran vishing calls impersonating named security staff to drive one employee to it. The employee submitted credentials and approved a push-based MFA prompt, yielding a short-lived, view-only session in ReliaQuest's identity provider dashboard. Device-trust controls blocked the session from reaching enterprise applications. ReliaQuest's response terminated the session, rotated the password, and reset all authentication factors; a 48-hour log review found no other compromised identities, no persistence, and no customer or company data access.