Social Engineering Attack Compromises ReliaQuest Employee Credentials, No Customer Data Accessed
What Happened – An attacker impersonated a ReliaQuest security employee, called multiple staff members (vishing) and directed a victim to a fraudulent ReliaQuest‑claims SSO login page hosted behind a CDN. The employee entered valid credentials and approved an MFA push, granting the attacker view‑only access to the identity dashboard. Device‑trust controls blocked any further application access and no customer data was exposed.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a real‑world breach of SOC 2 CC6.1 (Logical Access Controls) – the very control you must document and test.
- Highlights the need for continuous evidence of MFA enforcement, device‑trust enforcement, and timely revocation of compromised credentials as part of your audit trail.
- Shows that robust security‑awareness training can reduce the likelihood of successful vishing attacks, a key element of the SOC 2 CC6.2 “Security Awareness” control.
Who Is Affected – Cybersecurity service providers (MSSPs), SaaS platforms handling sensitive client data, and any organization that relies on SSO/MFA for privileged access.
Recommended Actions
- Map the incident to SOC 2 CC6.1/CC6.2 controls, capture logs of the unauthorized session as audit evidence.
- Conduct an immediate phishing‑vishing simulation and refresh security‑awareness training for all staff.
- Enforce adaptive MFA that requires contextual verification beyond a simple push (e.g., hardware token, biometric).
- Review and tighten device‑trust policies; ensure continuous monitoring of SSO activity.
Source: BleepingComputer
Technical Notes – Attack vector: vishing → fake SSO page (look‑alike domain reliaquest.claims). MFA push approved, view‑only dashboard access. No CVEs involved; the breach leveraged social engineering and insufficient verification of login URLs.