Cyber Incident Victim: ReliaQuest
Timeline
Summary
ReliaQuest reported that a ShinyHunters social engineering campaign briefly exposed its identity dashboard after attackers used a lookalike domain to host a fake single sign‑on page and called employees posing as security staff to obtain credentials. One employee entered a password and approved a push notification, granting the attacker a view‑only session on the dashboard while no applications, systems or customer data were accessed. The firm stated that claims of compromise or ransomware were false, noting that device trust controls prevented unauthorized access and that containment actions terminated the session, expired the password and reset authentication factors. Analysis by SOCRadar concluded the exchanged screenshots illustrated pressure tactics and public taunting but did not substantiate a breach or demonstrate network access.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On August 17, ReliaQuest posted on X and was replied to by a member of the ShinyHunters group with what appeared to be screenshots of its Okta dashboard and the message “Who's hunting who?”. The exchange was subsequently removed from X, but the screenshots reappeared on a ShinyHunters‑linked leak site on August 23, according to SOCRadar. Prior to this, ReliaQuest had been investigating a new campaign by ShinyHunters that used .claims domains in social engineering attacks. On August 22, the threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign‑on page behind a content delivery network. The actor then called multiple ReliaQuest teammates, each time posing as a security employee by name, in an attempt to steer them toward the fake page. One teammate entered their password and approved the push notification on their phone. That action handed the attacker a brief session on ReliaQuest’s identity dashboard. ReliaQuest emphasized that the access was view only and that no applications, systems, or customer data were accessed despite the actor’s attempts.

ReliaQuest publicly stated that claims of compromise or ransomware were false. The company noted that its defense‑in‑depth approach assumes a threat actor will eventually phish an account and that device trust controls prevent non‑ReliaQuest devices from accessing any application or system. Containment actions included terminating the attacker’s sessions, expiring the compromised password, and resetting every authentication factor. SOCRadar’s analysis of the incident supported ReliaQuest’s position, stating that the ShinyHunters’ posts illustrate pressure tactics and public taunting but do not substantiate a breach claim or demonstrate access to ReliaQuest networks. No further impact on customers, systems, or data was reported as a result of the incident.