ReliaQuest, a cybersecurity firm, has confirmed that one of its employees was targeted in a social engineering attack that resulted in temporary, view-only access to an internal identity dashboard. The incident, which occurred after an attacker impersonated a security team member, was subsequently claimed by the ShinyHunters data extortion group.
The attack involved an individual making calls to multiple ReliaQuest employees, attempting to direct them to a fraudulent single sign-on (SSO) page hosted behind a content delivery network. This phishing page was reportedly on a lookalike domain, specifically `reliaquest.claims`, and the attacker used the name of a legitimate security employee during these vishing attempts.
One employee ultimately fell victim to the deception, entering their credentials on the fake SSO page and approving a multi-factor authentication (MFA) push notification. This action granted the attacker temporary, view-only access to ReliaQuest's identity dashboard. However, the company's device-trust controls successfully prevented any subsequent attempts to access applications through the dashboard.
ReliaQuest stated that no applications or systems were accessed beyond the identity dashboard, and no customer data was compromised. The company immediately terminated the attacker's sessions, revoked the exposed password, and reset all authentication tokens. An internal investigation found no evidence of access to other accounts, applications, or data, nor any indication that the attacker established persistence on ReliaQuest's systems. The firm also audited its control fidelity, device trust, and on-network access since August 21 and found no suspicious activity.
The incident follows a prior alert from ReliaQuest's Threat Research team regarding a widespread ShinyHunters campaign. In a now-deleted post, ReliaQuest had warned that ShinyHunters was registering `.claims` domains, incorporating targeted organizations' names, to impersonate help desks and IT teams.
Shortly after the attack, a newly created X account, believed to be linked to ShinyHunters, replied to ReliaQuest's earlier post with the message "Who's hunting who?" and shared screenshots purporting to show a compromised Okta SSO account belonging to a ReliaQuest employee. ShinyHunters subsequently published these same screenshots on their data leak site. Both ReliaQuest's and the alleged threat actor's posts were later removed from X.
ShinyHunters, in claiming responsibility, referenced ReliaQuest's earlier reporting on the group, stating, "this time the post is about you, not us." The group also affirmed that their access was view-only and did not extend to any applications, systems, or customer data, echoing ReliaQuest's own findings. They specifically stated that "no additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established."






