On August 22, 2026, an employee at ReliaQuest, a cybersecurity firm, received a phone call from someone claiming to be a named member of the company’s own security team. The caller directed the employee to authenticate through what appeared to be the company’s single sign-on portal. The employee did. The site was a fake, the domain reliaquest.claims was registered by the attacker hours earlier, and the password and an MFA push approval went straight to the extortion group ShinyHunters. What stopped the attack from going further had nothing to do with whether the employee should have known better. It had everything to do with a device-trust control that blocked unmanaged devices from accessing business applications after the credential was surrendered.
This incident is a textbook social engineering defence scenario for 2026. CrowdStrike documented a doubling of vishing (voice phishing) attacks in the first half of this year, and ReliaQuest now provides the clearest public example of why that trend demands a response beyond email security tooling. ShinyHunters deployed a replica SSO portal on a content delivery network to evade detection, researched the names of real ReliaQuest security employees, and used those names as the pretext for the call. The entire campaign required no malware, no vulnerability, and no sophisticated technical capability. It required a phone number and preparation. ReliaQuest confirmed that zero business data, customer environments, or enterprise systems were accessed. ShinyHunters listed the company on its leak site on August 23 and shared screenshots of the compromised identity dashboard, but SOCRadar found no validated stolen data and no ransom demand.
The lesson is not that the employee failed. The lesson is that social engineering defence cannot depend on every employee making the right call under a pressured, plausible scenario. Organizations that have built a program around managing human cyber risk as an operational discipline, including verification protocols that employees are trained to follow reflexively, are far better positioned than those relying on annual awareness modules to prevent what is a live and evolving human attack surface.
What the healthcare sector advisory makes clear
On August 24, the American Hospital Association’s Health-ISAC issued a white advisory warning healthcare organizations about ShinyHunters-linked social engineering and identity-targeting campaigns. Healthcare is a high-value target because patient data carries significant resale value, and because IT and security help desks in that sector process urgent, interruption-driven requests all day. A caller posing as a colleague asking for quick account assistance is not a suspicious pattern in that environment. It is a routine occurrence being exploited.
In Canada, the stakes are concrete. Manitoba’s Health Sciences Centre was struck by a ransomware attack in August 2026 that disrupted door access systems, elevators, and HVAC systems, two years after the provincial auditor general recommended annual cybersecurity testing and more security awareness training for Shared Health staff. The gap between a recommendation in an audit report and a running training programme is the gap where these incidents begin.
One practical step for this week
Establish a verification protocol for your IT and security help desk and test it. When a caller claims to be a colleague and requests an urgent action, whether that is approving an MFA push, clicking a link, or providing access credentials, the trained response should be to end the call and call back through a verified internal number. Run one drill this week with a specific team. If any employee is unsure what the protocol is, that is the finding. POPP3R’s security awareness services build and run these drills as part of an ongoing programme, so the knowledge is embedded in muscle memory, not just a policy document.
In our work with Canadian organizations of all sizes, we consistently see that the single biggest predictor of how badly an incident damages an organization is not whether someone clicked, it is whether anyone reported it. The story above is a textbook example of why reporting culture matters more than click prevention.
Sources
- ReliaQuest: A Social Engineering Attempt Against ReliaQuest: What We Found (August 2026)
- BleepingComputer: ReliaQuest confirms failed data-theft attempt after ShinyHunters breach (August 24, 2026)
- AHA H-ISAC: ShinyHunters-Linked Social Engineering and Identity-Targeting Campaign (August 24, 2026)
- CBC News: Ransomware attack on Health Sciences Centre affects doors, ventilation and air conditioning (August 2026)