One of the more useful security incidents of the month came from ReliaQuest, not because of what the attacker achieved, but because the company published exactly what happened.
On 22 August, attackers registered a lookalike domain, built a fake ReliaQuest SSO page, and began phoning employees while impersonating a real member of the company's security team. One employee entered their password into the fake page and approved the MFA push on their phone. At that moment the attacker held a valid session on ReliaQuest's identity dashboard.
What happened next is the story
The attacker tried to move from the identity dashboard into ReliaQuest's applications, and could not. Device trust controls refused the attacker-controlled machine, while ReliaQuest terminated the session, expired the employee's password and reset their authentication factors.
According to the company, no business applications were accessed, no customer data was touched, and the attacker established no persistence. A successfully phished employee did not become a breach, because the phish was never the last control.
ReliaQuest's own framing is the part worth stealing: the company says it assumes somebody will eventually get phished, and designs for what happens after. ShinyHunters later claimed the attack and publicly taunted the company over the compromised account, although ReliaQuest has not attributed it. Readers with long memories will note the irony: it was ReliaQuest's own research into the Helix group that we covered in Issue #001.
Why identity teams should care
Most security programmes still treat the credential phish as the failure. This incident is a working demonstration of the better model: treat it as the expected event, and measure your programme by the blast radius that follows.
Three questions fall straight out of it. Would device trust have stopped an attacker-controlled machine in your environment, or does a valid session work from anywhere? How quickly would the session have been found and killed? And who resets the authentication factors, and how fast, once it is?
The phishing awareness training still matters. But somebody in your organisation will eventually type their password into the wrong box and approve the push. The difference between an incident report and a breach notification is everything that sits behind that moment.