Executive Summary

In August 2026, cybersecurity firm ReliaQuest fell victim to a sophisticated social engineering attack orchestrated by the ShinyHunters extortion group. Attackers impersonated ReliaQuest security team members via phone calls, directing employees to a fraudulent SSO page hosted on the lookalike domain reliaquest.claims. One employee was successfully deceived into entering credentials and approving an MFA push notification, granting attackers temporary view-only access to ReliaQuest's Okta identity dashboard. However, device-trust controls successfully prevented access to applications and systems, limiting the breach's scope to credential exposure only.

This incident highlights the evolving sophistication of social engineering attacks targeting identity systems, particularly as threat actors increasingly combine vishing techniques with credential harvesting. The attack demonstrates how even cybersecurity companies with robust controls can be vulnerable to human-focused attack vectors, emphasizing the critical need for comprehensive identity protection beyond traditional MFA implementations.

Why This Matters Now

Identity-based attacks are surging as traditional perimeter defenses become obsolete, with social engineering now targeting even cybersecurity professionals. This incident exposes the urgent need for device trust controls and behavioral analytics to prevent credential-based breaches.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used social engineering via phone calls to trick an employee into entering credentials on a fake SSO page and approving an MFA push notification, demonstrating that MFA alone cannot prevent sophisticated social engineering attacks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would be highly relevant to this ShinyHunters social engineering attack, as segmentation controls could limit the blast radius of compromised credentials and reduce lateral movement opportunities within ReliaQuest's cloud infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation and DNS filtering policies would likely reduce exposure to malicious domains and constrain attacker reachability to internal SSO infrastructure through controlled ingress points

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware segmentation policies would likely constrain the scope of dashboard access and reduce privilege expansion by limiting reachability between identity management systems and downstream applications

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation between cloud workloads would likely limit lateral movement paths and constrain attacker reachability across application tiers through identity-scoped network access controls

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Network visibility and anomaly detection would likely identify unauthorized session patterns and reduce command channel establishment through behavioral monitoring of east-west traffic flows

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely constrain unauthorized data flows and reduce exfiltration opportunities by limiting outbound network paths from compromised identity management systems

Impact (Mitigations)

Residual business risk would likely be constrained to identity metadata exposure with reduced scope for customer data compromise or operational disruption through network isolation

Impact at a Glance

Affected Business Functions

  • Identity and Access Management (IAM)
  • Security Operations Center (SOC)
  • Threat Intelligence Services
  • Customer Security Platforms
Operational Disruption

Estimated downtime: 1 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Limited exposure to employee SSO credentials and identity dashboard metadata. No customer data, business applications, or sensitive corporate systems were accessed. Only view-only access to identity management interface was achieved before being blocked by device trust controls.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement even with valid credentials
  • Deploy Multicloud Visibility & Control to detect anomalous authentication patterns and suspicious login attempts
  • Strengthen Egress Security & Policy Enforcement to block unauthorized data exfiltration attempts from compromised accounts
  • Enhance Threat Detection & Anomaly Response capabilities to identify social engineering attacks targeting employee credentials
  • Utilize Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous response to credential compromise incidents

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image