© 2026 CoolTechZone - Latest tech news,
product reviews, and analyses.

Cybersecurity firm targeted by social engineering attack


US cybersecurity firm ReliaQuest was the target of a social engineering attack in which attackers gained access to one of the company’s IT systems.

Before the threat actor launched its offensive, it registered a bogus domain and built a fake ReliaQuest single sign-on (SSO) page behind a content delivery network (CDN).

Next, posing as a security employee, the attackers called multiple workers of the cybersecurity firm in an attempt to steer them to the fake login page.

One of the workers of ReliaQuest fell for the trick, entered his password, and confirmed the push notification via a multi-factor authentication (MFA) app that was installed on his own device.

“That handed the attacker a brief session on our identity dashboard,” the cybersecurity organization says in a blog post detailing the attack so others can learn from this experience.

“The extent of the access was view only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched. The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place,” the company continues.

This is a clear example of a social engineering attack, a type of cyberattack in which a threat actor tries to manipulate a worker into doing something that compromises the defenses of a business. Instead of hacking his way into a corporate network or exploiting known technical vulnerabilities, the attacker “plays” on the sentiments of an employee.

In this case, the attacker succeeded in gaining access to one of ReliaQuest’s systems, but never got hold of any corporate, personal, or other sensitive information.

“This playbook is consistent with what we are seeing across the industry: an impersonation call, a throwaway lookalike domain registered and burned within the hour, a harvesting page behind a content delivery network, MFA push abuse, and a rapid attempt to enroll a new authenticator,” the cybersecurity firm concludes.

ReliaQuest doesn’t say who the threat actor was that tried to steal data from the company.

However, according to cybersecurity analyst and security researcher Dominic Alvieri, ransomware extortion group ShinyHunters has claimed responsibility for the social engineering attack on ReliaQuest.

ShinyHunters mentioned ReliaQuest on its leak site, but didn’t provide any details, such as what kind of data was stolen or how much, something the extortion group normally does.