2026-08-24NOTABLEReliaQuest denies a compromise claim and documents a vishing call that got one MFA push approved; device-trust binding is what capped it
ReliaQuest social-engineering attempt (August 2026)
incident · incident:reliaquest-social-engineering-attempt-2026-08 single-source-victim
Social-engineering attempt against the managed-detection vendor ReliaQuest, disclosed in its own account of 2026-08-23, which describes the attempt, sets out its investigation findings, and then states that circulating claims it had been compromised or hit by ransomware are false. Per that account: a lookalike domain and counterfeit single-sign-on page behind a content delivery network, cold calls to multiple employees impersonating a named member of ReliaQuest's own security staff, one password entry and MFA-push approval yielding a view-only identity-dashboard session, and every onward application-access attempt denied by a device-trust policy requiring a managed device. ReliaQuest names no actor, and its article does not describe the claim it denies (ReliaQuest, 2026-08-23).
Coverage
1
first 2026-08-24 → last 2026-08-24
Latest activity
2026-08-24
ReliaQuest denies a compromise claim and documents a vishing call that got one MFA push approved…
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
1
1 hosts
Defender insights
What each entry about ReliaQuest social-engineering attempt (August 2026) tells a defender to do, newest first.
Triage
Story timeline
ATT&CK techniques (5 across 6 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentAcquire Infrastructure: Domains
- Initial AccessValid Accounts: Cloud Accounts · Phishing: Spearphishing Voice
- PersistenceValid Accounts: Cloud Accounts
- Privilege EscalationValid Accounts: Cloud Accounts
- StealthValid Accounts: Cloud Accounts · Social Engineering: Impersonation
- Credential AccessMulti-Factor Authentication Request Generation
Resource Development TA0042
T1583.001Acquire Infrastructure: Domains×1
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
T1566.004Phishing: Spearphishing Voice×1
Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
Credential Access TA0006
T1621Multi-Factor Authentication Request Generation×1
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Evidence: 2026-08-24/reliaquest-vishing-mfa-push-device-trust-contained · ATT&CK page ↗
Entries about ReliaQuest social-engineering attempt (August 2026) (1)
Where this entity is cited
Source distribution
- reliaquest.com1 (100%)