Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

ReliaQuest, a cybersecurity firm, has confirmed that one of its employees was targeted in a social engineering attack that resulted in temporary, view-only access to an internal identity dashboard. The incident, which occurred after an attacker impersonated a security team member, was subsequently claimed by the ShinyHunters data extortion group.
The attack involved an individual making calls to multiple ReliaQuest employees, attempting to direct them to a fraudulent single sign-on (SSO) page hosted behind a content delivery network. This phishing page was reportedly on a lookalike domain, specifically `reliaquest.claims`, and the attacker used the name of a legitimate security employee during these vishing attempts.
One employee ultimately fell victim to the deception, entering their credentials on the fake SSO page and approving a multi-factor authentication (MFA) push notification. This action granted the attacker temporary, view-only access to ReliaQuest's identity dashboard. However, the company's device-trust controls successfully prevented any subsequent attempts to access applications through the dashboard.
ReliaQuest stated that no applications or systems were accessed beyond the identity dashboard, and no customer data was compromised. The company immediately terminated the attacker's sessions, revoked the exposed password, and reset all authentication tokens. An internal investigation found no evidence of access to other accounts, applications, or data, nor any indication that the attacker established persistence on ReliaQuest's systems. The firm also audited its control fidelity, device trust, and on-network access since August 21 and found no suspicious activity.
The incident follows a prior alert from ReliaQuest's Threat Research team regarding a widespread ShinyHunters campaign. In a now-deleted post, ReliaQuest had warned that ShinyHunters was registering `.claims` domains, incorporating targeted organizations' names, to impersonate help desks and IT teams.
Shortly after the attack, a newly created X account, believed to be linked to ShinyHunters, replied to ReliaQuest's earlier post with the message "Who's hunting who?" and shared screenshots purporting to show a compromised Okta SSO account belonging to a ReliaQuest employee. ShinyHunters subsequently published these same screenshots on their data leak site. Both ReliaQuest's and the alleged threat actor's posts were later removed from X.
ShinyHunters, in claiming responsibility, referenced ReliaQuest's earlier reporting on the group, stating, "this time the post is about you, not us." The group also affirmed that their access was view-only and did not extend to any applications, systems, or customer data, echoing ReliaQuest's own findings. They specifically stated that "no additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established."





U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [

The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.