Skip to main content

folkfox

Skip to main content
Skip to content
MDR and Vendor Trust

The MDR Service Provider That Got Vished

A managed detection and response vendor whose entire pitch is catching social engineering just got socially engineered. The lesson is not embarrassment, it is a buyer's checklist hiding in plain sight.

Quick answerWhen the mdr service provider whose whole pitch is threat detection gets vished, the lesson is plain: demand device-level access architecture from vendors, not just an MFA checkbox on a sales deck.
Section 01

The MDR Service Provider That Got Vished#

A fox does not warn the henhouse and then leave the gate open, but that is roughly what happened to ReliaQuest, a managed detection and response vendor whose entire pitch to clients rests on catching exactly the kind of attack that caught its own staff. On 22 August 2026, an mdr service provider built to sniff out social engineering got socially engineered itself, and the story that follows is less a scandal than a stress test every buyer of a mdr service provider should read closely before signing anything.

40%

higher success rate for voice phishing than email phishing, per a Push Security review of Verizon's 2026 DBIR data

Push Security, review of Verizon DBIR 2026

Five days earlier, ReliaQuest's own threat research team had posted a public warning about a wave of lookalike-domain vishing campaigns, precisely the scent an mdr service provider is paid to track. ShinyHunters, the extortion crew behind the campaigns, replied under the handle @odysseusgroup with a taunt that read, in full, "Who's hunting who?" The posts were later deleted, as Help Net Security reported, but the challenge had landed, and five days on the fox found itself the quarry.

Vishing beats email phishing, industry-wide
Bullet chart comparing voice phishing and email phishing median click rates against a zero-click target, a benchmark any mdr service provider should know coldVoice phishing: 2 of 0Voice phishing2%Email phishing: 1.4 of 0Email phishing1.4%
Voice phishing simulations post a 2% median click rate against email phishing's 1.4%, a 40% gap, per Push Security's reading of Verizon's 2026 DBIR data. Zero is the only safe target for either.

Read that gap the way you would read a hedgerow at dusk: the shape rarely changes, only who is standing in it. Voice calls succeed where emails fail because a ringing phone triggers an urgency a filtered inbox never does, and no security awareness training fully removes the instinct to trust a colleague who sounds like a colleague. That is precisely the mechanism ShinyHunters used against ReliaQuest, down to the letter.

The scale behind that single incident is worth sitting with too. CrowdStrike's own 2026 threat hunting findings, as covered by Help Net Security, put vishing-related intrusions up 134% between 2024 and 2025, with early 2026 already running at twice the pace of the prior six months. ReliaQuest was not an outlier target, it was simply the fox caught in a trend already prowling every hedgerow in the sector.

The attackers registered a lookalike domain a single character removed from ReliaQuest's own, then stood a convincing fake single sign-on page behind a content delivery network so it would resolve fast and clean. They phoned multiple employees, each call opening with the name of a real member of ReliaQuest's own security team, a detail precise enough to prowl straight past normal suspicion. One employee, following what felt like a routine instruction from a trusted colleague, typed credentials into the fake page and then approved a push notification that looked, and felt, entirely ordinary.

That is worth remembering the next time a vendor pitches security awareness training as the whole answer. A Harvard Kennedy School and Meta study of more than 4,100 adults, covered by Help Net Security, found that persuasiveness, not how human the voice sounded, drove compliance: each step up in a script's persuasiveness raised the odds of compliance by a factor of 2.58, and callers with obviously synthetic voices still succeeded regardless. The script does the persuading. No amount of training a person to spot a robotic voice defends against a script this good, which is exactly why the control that mattered at ReliaQuest sat below the human layer entirely.

mdr service provider vishing attack response, a wary fox with a phone
One phone call, one lookalike domain, one employee who trusted the voice on the line.

ReliaQuest's own account of what happened next is precise enough to quote directly. The intrusion produced, in the company's words, "a single identity session with view-only access to our identity dashboard," and every further attempt to reach other systems was "consistently denied due to the security controls in place." No ReliaQuest applications or systems were accessed, and no customer data was ever touched, the company confirmed in its own incident writeup.

The detail that matters for any shortlist of managed detection and response services is which control actually did the work. It was not the MFA step; the employee approved that push notification willingly, believing it was routine. What stopped the attackers cold was a second, separate gate: device-level trust. The session had opened on a machine ReliaQuest did not recognise as company owned, so business applications and customer data stayed out of reach regardless of how convincing the login had been. ReliaQuest confirmed "no additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed" and that "no persistence was established."

That distinction, MFA versus device trust, is the whole argument of this piece, and it is worth sitting with before the next fire drill. An mdr service provider markets the MFA badge because it is easy to show a client on a slide. Device-level architecture is harder to demo and impossible to fake, which is exactly why it is the harder, better test of a vendor's real security posture.

Section 02

Why ShinyHunters Taunted the Threat Hunters First#

Most vendor breach stories folkfox tracks follow a predictable script: quiet disclosure, a defensive blog post, silence. This one did not follow the script, because ShinyHunters wanted an audience for the joke as much as the intrusion.

On 17 August 2026, ReliaQuest's threat research desk posted a public warning about a wave of ShinyHunters lookalike-domain campaigns, the same vishing playbook the group has run against Salesforce customers since May 2025, when voice-phishing calls persuaded staff to connect a malicious app and ultimately pulled more than a billion records out the back door, as Krebs on Security documented. An account posting as @odysseusgroup replied within hours: "Who's hunting who?" The exchange, and the original warning post, were both later deleted, but the taunt had landed and the trap had been set.

Five days on, on 22 August, the vishing calls went out. By 23 August, ShinyHunters had posted screenshots to their leak site appearing to show Okta single sign-on access, captioned with a line built for maximum sting: "This time the post is about you, not us." ReliaQuest's own account and the attackers' screenshots do not agree on how far the intrusion actually reached, and Help Net Security's reporting is candid that the truth of that gap likely sits somewhere between the two versions.

How far the attack chain actually got
How far the attack chain actually gotWaterfall chart showing an illustrative attack chain building through credential theft and a fraudulent MFA approval to a view-only session, then reconciling to zero after business apps and customer data were deniedVishing call: +5 (running total 5)Creds entered: +25 (running total 30)MFA approved: +35 (running total 65)Dashboard: +20 (running total 85)Apps denied: -45 (running total 40)Data denied: -40 (running total 0)Blocked: 00255075100Vishing call+5Creds entered+25MFA approved+35Dashboard+20Apps denied-45Data denied-40Blocked0
Illustrative scoring of the chain, not a measured industry metric: the intrusion built toward a view-only session, then hit a wall of device-level denials that reconciled the whole run back to zero systems reached.

The exchange did not stay inside the security industry's private channels for long. By the next morning it had surfaced on Reddit, in a thread that put the uncomfortable point more plainly than either party's official statement had.

u/PureVPNcom
Push notification MFA does not provide sufficient protection against targeted social engineering when the user personally approves a fraudulent request. What actually stopped the damage was layered access controls that didn't trust a logged-in identity dashboard session as enough to reach production systems.
27 August 2026, r/PureVPNforTeamsView on Reddit

Read past the taunting and the finding holds regardless of which screenshot you trust: push-notification MFA does not stop a targeted social engineer once a person personally approves the fraudulent request, and it never has. What held the line was layered, device-aware access design, not the login screen. Any mdr service provider that markets MFA as its headline defence is selling the wrong story, and any buyer who accepts it as proof of resilience is buying the wrong story too.

Section 03

MDR vs EDR: The Difference This Breach Just Proved#

Step back from ReliaQuest for a moment and answer a simpler question first. Managed detection and response, which answers what does mdr stand for in the plainest terms available, pairs endpoint detection and response (EDR) tooling with a round-the-clock human team who hunt, triage and respond on a client's behalf.

EDR is the sensor. MDR is the sentinel watching the sensor, and the difference is entirely about who is awake at 3am when the alert fires. CrowdStrike's own explainer on the category puts it plainly: MDR "introduces human expertise, mature processes, and threat intelligence" on top of endpoint tooling, cutting an industry benchmark of 277 days to detect a breach down toward minutes rather than months.

Do the maths on 3am coverage#

For a buyer choosing among the roster of managed detection and response services on any shortlist, or vetting a single mdr service provider already on the table, that human layer is the entire value proposition, which is exactly why ReliaQuest's own vishing incident matters more than a routine phishing near-miss at an ordinary software vendor. The humans being socially engineered were the humans a client pays to be diligently, unsociably engineered against exactly this.

EDR is a tool a buyer operates, MDR is a team a buyer trusts, and ReliaQuest's own incident is a reminder that the second half of that sentence carries the real risk.
QuestionEDR aloneMDR
Who watches the alert at 3am?Nobody, until someone logs inA staffed analyst team
Who is the attack surface?Your endpoints onlyYour endpoints and the vendor's own staff
What proves resilience?A feature listA tested, layered access architecture
What should you ask for?A demoAn incident history and a device trust policy

Ask any of the top mdr providers you are evaluating to walk you through their own device trust architecture before you ask them to walk you through yours. If they cannot answer quickly, that is the answer.

Section 04

The Real Differentiator Is Device Trust, Not an MFA Badge#

Marketing a security vendor is an unusually honest business some days and an unusually vague one on others, and the difference usually comes down to which claims a prospect can actually verify. "We use MFA" is a claim. A named, testable device trust policy is evidence, and evidence is what should decide which mdr service provider gets the contract.

The gap between those two things is not folkfox's opinion, it is written into federal guidance. NIST's digital identity standard is blunt about why a manually approved push notification falls short: such authenticators "SHALL NOT be considered verifier impersonation resistant," precisely because approving a prompt on a phone does nothing to bind that approval to the specific session an attacker is running on an entirely different machine, per NIST SP 800-63B.

The sentence a good vendor says instead#

Microsoft's own access control documentation treats device compliance as a separate lever from MFA entirely, not a synonym for it: an administrator can require a session to run from a device already registered and marked compliant, a check that fires after multi-factor authentication clears and asks a completely different question. That second gate, not the first, is what boxed ReliaQuest's attackers into a read-only corner.

MFA claimed, unverified

We protect every account with multi-factor authentication.

Device trust, named and testable

Every session also requires a device our identity team has already registered and marked compliant, independent of the MFA step itself.

Push the sales team past the first sentence and toward the second one. If they cannot describe a control that survives an employee doing exactly the wrong thing while believing entirely the right instruction, they are describing a policy, not a defence. An mdr service provider that cannot name that second gate in one sentence has not built it.

Section 05

What to Ask Before You Sign With Any MDR Service Provider#

None of this is abstract for folkfox's own clients in cybersecurity marketing, who are, more often than not, trying to differentiate one mdr service provider's positioning from six others all promising the same round-the-clock vigilance. The ReliaQuest incident hands the whole sector a genuinely useful gift: a real, public, honestly reported test case for what actually holds under pressure, rather than a hypothetical in a whitepaper.

It sits alongside two other stories folkfox has already covered this year that point the same direction. Fortinet's acquisition of Virtue AI added an MDR layer built explicitly around behavioural detection rather than signature matching, a bet that the humans watching the alerts need sharper tooling, not just more of it (see folkfox on MDR services and the Virtue AI acquisition). Entra ID's own strong score on a recent identity posture benchmark made a related point from the vendor side: identity tooling can be excellent and still get walked past by a convincing phone call, which is exactly why device-level checks matter as a second, independent gate (see folkfox on identity security posture management).

Buyers should also press providers on how they handle disclosure once something does go wrong, because ReliaQuest's own transparency, awkward taunting and all, is arguably the most reassuring part of this whole story. Compare that openness with the alternative folkfox covered when LG Uplus ran South Korea's first global vulnerability disclosure programme, a structural commitment to finding problems before an attacker does rather than after (see folkfox on vulnerability disclosure programmes).

So the brief for any marketing team representing an mdr service provider is not to hide the possibility of a breach, it is to prove, in public and in specific technical language, exactly which layered controls would catch one. That is a harder story to write than "we use MFA," and it is the only story a sceptical buyer will actually believe.

MFA is the sentence every vendor says. Device trust is the sentence only the honest ones can finish.
folkfox, on marketing an mdr service provider after ReliaQuest

Building that story, the quotable, sourced, technically honest kind that survives a sceptical security buyer's first search, is a content and search problem before it is anything else. It is the discipline behind folkfox's own SEO and GEO services and content marketing services, and it pairs naturally with the demand-generation work our PPC team runs alongside it for clients competing on exactly this kind of trust signal.

Questions

Frequently asked questions#

What does MDR stand for?

MDR stands for managed detection and response, a security service that pairs endpoint detection and response tooling with a dedicated human team who monitor, investigate and respond to threats around the clock, rather than leaving a client's own staff to interpret every alert alone.

MDR vs EDR, what's actually different?

EDR is the sensor sitting on an endpoint, recording and flagging suspicious behaviour. MDR adds a staffed team who watch that sensor, chase down the alerts it raises and act on them, the difference that mattered when ReliaQuest's own detection vendor had to detect an attack on itself.

How do I choose a good mdr service provider?

Ask for a named incident history rather than a clean slate; every serious vendor has one. Then ask specifically how device trust and session controls work independently of MFA, since that is the layer that actually held during ReliaQuest's own vishing incident in August 2026.

What actually happened in the ReliaQuest vishing attack?

In August 2026, ShinyHunters registered a lookalike domain, stood up a fake ReliaQuest login page and phoned staff impersonating a real colleague. One employee entered credentials and approved a fraudulent MFA prompt, giving attackers a brief, view-only session on an identity dashboard and nothing more, because device trust controls blocked the rest.

Can multi-factor authentication really be bypassed by vishing?

Yes, when a person is talked into approving the prompt themselves. NIST's own guidance notes that manually approved push notifications are not resistant to this kind of impersonation, which is why device-level checks matter as a genuinely separate control, not a backup for MFA.

What should I ask any of the top mdr providers before signing?

Ask how they would have stopped exactly what happened to ReliaQuest: a vished employee with valid, approved credentials. If the answer is only "we use MFA," keep shopping among the other top mdr providers on your list.

Are managed detection and response services themselves ever hacked?

Yes. ReliaQuest's own August 2026 incident is a rare, publicly documented example of a managed detection and response provider's staff being successfully socially engineered, which is precisely why buyers should judge vendors on architecture, not on the absence of an incident report.

Keep reading

Read more on this topic#

Ready to market real device trust, not just an MFA badge?

Turning layered security architecture into content a sceptical buyer actually trusts is what folkfox does for mdr service provider marketing teams, built on search visibility that survives the next vishing headline.