ThreatCluster

Social Engineering Attack Targets ReliaQuest Employees

First seen 24 Aug 2026, 20:24 UTC GbhackersCybersecuritynews 51

Article Content

Browse articles
ThreatCluster

On August 22, 2026, ReliaQuest reported a social engineering attack where hackers impersonated security staff to obtain credentials. The attackers used a spoofed domain to trick an employee into approving a malicious multi-factor authentication (MFA) request. This incident temporarily exposed a single identity session with view-only access to ReliaQuest's systems. However, the company's layered security controls prevented unauthorized access to internal applications and sensitive data. The attack highlights the risks associated with social engineering tactics in corporate environments. ReliaQuest is currently investigating the incident and has implemented additional security measures to mitigate future risks.

Key Points: • Hackers impersonated ReliaQuest security staff to steal credentials. • The attack involved a spoofed domain and a fraudulent MFA request. • ReliaQuest's security controls prevented access to sensitive data.

Timeline

2026-08-22
Social engineering attack detected
Threat actors impersonated security personnel to steal credentials via a spoofed domain.
Gbhackers
2026-08-22
Employee credentials compromised
An employee was tricked into approving a malicious MFA request, exposing a single identity session.
Cybersecuritynews