ReliaQuest Employee Falls for Vishing Attack, Handing ShinyHunters Temporary Access to Identity Dashboard
What Happened — An employee at cybersecurity firm ReliaQuest was tricked by a phone‑based social‑engineering (vishing) call. The attacker convinced the employee to enter their password on a look‑alike SSO page and approve an MFA push, granting a brief, view‑only session into the company’s identity‑management console. No customer data or production systems were accessed before the session was terminated.
Why It Matters for Compliance & Audit Readiness
- Illustrates a real‑world breach of SOC 2 CC6.1 (Logical Access Control) despite MFA being in place – a control that must be documented and continuously monitored.
- Highlights the need for evidence‑ready processes (session logs, device‑trust enforcement, MFA approval records) that prove the effectiveness of access‑control safeguards during an audit.
- Reinforces that security awareness programs must cover phone‑based phishing (vishing) to satisfy SOC 2 CC6.2 (Security Awareness Training) requirements.
Who Is Affected – Cybersecurity service providers, Managed Security Service Providers (MSSPs), and any organization that relies on SSO and MFA for privileged access.
Recommended Actions
- Review and tighten MFA policies: enforce device‑trust checks and limit session scope for privileged consoles.
- Capture and retain MFA approval logs, session‑termination events, and device‑trust validation as continuous audit evidence.
- Expand security‑awareness training to include vishing scenarios and conduct regular simulated phone‑phishing exercises.
- Map these controls to SOC 2 CC6.1/CC6.2 and ensure evidence collection is automated for audit readiness.
Technical Notes — Attack vector: vishing (phone‑based phishing) → fake SSO page hosted behind a CDN. Credential: valid password + approved MFA push. Data accessed: view‑only identity dashboard; no downstream applications or customer data. Source: Help Net Security