Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

ReliaQuest Employee Falls for Vishing Attack, Handing ShinyHunters Temporary Access to Identity Dashboard

ReliaQuest confirmed that a staff member was duped by a phone‑based social‑engineering call, entered their password on a fake SSO page and approved an MFA push, granting attackers a brief view‑only session in the identity console. No customer data or production systems were accessed, underscoring the importance of robust SOC 2 access‑control evidence.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

ReliaQuest Employee Falls for Vishing Attack, Handing ShinyHunters Temporary Access to Identity Dashboard

What Happened — An employee at cybersecurity firm ReliaQuest was tricked by a phone‑based social‑engineering (vishing) call. The attacker convinced the employee to enter their password on a look‑alike SSO page and approve an MFA push, granting a brief, view‑only session into the company’s identity‑management console. No customer data or production systems were accessed before the session was terminated.

Why It Matters for Compliance & Audit Readiness

  • Illustrates a real‑world breach of SOC 2 CC6.1 (Logical Access Control) despite MFA being in place – a control that must be documented and continuously monitored.
  • Highlights the need for evidence‑ready processes (session logs, device‑trust enforcement, MFA approval records) that prove the effectiveness of access‑control safeguards during an audit.
  • Reinforces that security awareness programs must cover phone‑based phishing (vishing) to satisfy SOC 2 CC6.2 (Security Awareness Training) requirements.

Who Is Affected – Cybersecurity service providers, Managed Security Service Providers (MSSPs), and any organization that relies on SSO and MFA for privileged access.

Recommended Actions

  • Review and tighten MFA policies: enforce device‑trust checks and limit session scope for privileged consoles.
  • Capture and retain MFA approval logs, session‑termination events, and device‑trust validation as continuous audit evidence.
  • Expand security‑awareness training to include vishing scenarios and conduct regular simulated phone‑phishing exercises.
  • Map these controls to SOC 2 CC6.1/CC6.2 and ensure evidence collection is automated for audit readiness.

Technical Notes — Attack vector: vishing (phone‑based phishing) → fake SSO page hosted behind a CDN. Credential: valid password + approved MFA push. Data accessed: view‑only identity dashboard; no downstream applications or customer data. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/25/reliaquest-breach-social-engineering/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →