started · updated
ReliaQuest contains social engineering attack by ShinyHunters
ReliaQuest recently disclosed a targeted social engineering attack by the group ShinyHunters. On August 22, 2026, attackers used vishing and a spoofed single sign-on (SSO) portal to impersonate security staff. One employee was persuaded to approve a malicious multi-factor authentication (MFA) request, granting attackers temporary view-only access to an identity dashboard. ReliaQuest stated that its device-trust controls prevented the attackers from accessing internal applications, customer data, or business systems.
Broadly, cybersecurity trends show a significant rise in identity-based threats. A Cisco Talos report indicates that phishing accounted for over half of incident response engagements in Q2 2026, up from one-third in the previous quarter. Authentication abuse also saw a sharp increase, appearing in 65% of engagements. Attackers are increasingly using methods like adversary-in-the-middle (AitM) proxies and session-token theft to bypass MFA.
Additionally, the Mirage2FA phishing toolkit has been observed targeting thousands of companies, primarily in the US, by abusing Microsoft 365 login flows to steal session cookies. This campaign has potentially compromised thousands of email addresses across various industries, including technology and manufacturing.
Entities
Any.run · Cisco Talos · Microsoft · OKTA · ReliaQuest · ShinyHunters