LIVE · cybersecurity feed
Live wire
CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accounts
breach

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

zeroday.news ·

ReliaQuest, a cybersecurity firm, has confirmed that one of its employees was targeted in a social engineering attack that resulted in temporary, view-only access to an internal identity dashboard. The incident, which occurred after an attacker impersonated a security team member, was subsequently claimed by the ShinyHunters data extortion group.

The attack involved an individual making calls to multiple ReliaQuest employees, attempting to direct them to a fraudulent single sign-on (SSO) page hosted behind a content delivery network. This phishing page was reportedly on a lookalike domain, specifically `reliaquest.claims`, and the attacker used the name of a legitimate security employee during these vishing attempts.

One employee ultimately fell victim to the deception, entering their credentials on the fake SSO page and approving a multi-factor authentication (MFA) push notification. This action granted the attacker temporary, view-only access to ReliaQuest's identity dashboard. However, the company's device-trust controls successfully prevented any subsequent attempts to access applications through the dashboard.

ReliaQuest stated that no applications or systems were accessed beyond the identity dashboard, and no customer data was compromised. The company immediately terminated the attacker's sessions, revoked the exposed password, and reset all authentication tokens. An internal investigation found no evidence of access to other accounts, applications, or data, nor any indication that the attacker established persistence on ReliaQuest's systems. The firm also audited its control fidelity, device trust, and on-network access since August 21 and found no suspicious activity.

The incident follows a prior alert from ReliaQuest's Threat Research team regarding a widespread ShinyHunters campaign. In a now-deleted post, ReliaQuest had warned that ShinyHunters was registering `.claims` domains, incorporating targeted organizations' names, to impersonate help desks and IT teams.

Shortly after the attack, a newly created X account, believed to be linked to ShinyHunters, replied to ReliaQuest's earlier post with the message "Who's hunting who?" and shared screenshots purporting to show a compromised Okta SSO account belonging to a ReliaQuest employee. ShinyHunters subsequently published these same screenshots on their data leak site. Both ReliaQuest's and the alleged threat actor's posts were later removed from X.

ShinyHunters, in claiming responsibility, referenced ReliaQuest's earlier reporting on the group, stating, "this time the post is about you, not us." The group also affirmed that their access was view-only and did not extend to any applications, systems, or customer data, echoing ReliaQuest's own findings. They specifically stated that "no additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established."

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

South Korean startup platform breach exposes key management failures

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]

cloud

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions

ransomware

Tricky 'SynkLoader' Multitool May Herald Ransomware

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

security

Your data doesn’t die when you do (Lock and Code S07E17)

This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.

malware

ToxicPanda Banking Trojan Matures into Enterprise Threat

The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.

security

AliExpress caught using silent audio to fingerprint visitors’ browsers

Silent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.