Breaking
SecurityDeveloping Story

Limited Breach: ReliaQuest Confirms Hack

ReliaQuest says ShinyHunters accessed an identity dashboard briefly but no customer data was compromised.

··1 hour ago·3 min read
a laptop on a table
Photo by PiggyBank on Unsplash

Cybersecurity firm ReliaQuest has confirmed that it was targeted in a social engineering attack attributed to ShinyHunters, but the company maintains that the impact was limited. The incident, which unfolded over a weekend, prompted the company to publicly address claims of a more severe compromise.

Weekend Social Engineering Attack

ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the ‘company.claims’ URL pattern. The company also warned that the hacker gang has been expanding its social engineering tactics to include legal team impersonation alongside IT and help desk impersonation.

In response to that now-deleted post, someone shared several screenshots that appeared to show access to a ReliaQuest Okta dashboard. The same screenshots were posted on ShinyHunters’ website, along with a message taunting the security firm.

ReliaQuest addressed the incident on Monday, admitting it had been targeted in a social engineering attack over the weekend. According to the company, the hackers registered a fake domain and set it up to host a ReliaQuest SSO phishing page.

Fake Domain and Phishing Page

The attackers registered a domain that mimicked ReliaQuest's legitimate SSO portal. They then called multiple ReliaQuest employees, each time posing as a security employee by name, attempting to steer them toward the fake page. The tactic relied on impersonating trusted internal figures, a method that has become increasingly common in social engineering campaigns.

One employee fell for the ruse, entering their password and approving a push notification on their phone. That action handed the attacker a brief session on the company's identity dashboard. ReliaQuest emphasized that the session was short-lived.

“The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”

— ReliaQuest, via a statement provided to SecurityWeek

View-Only Access and Denied Attempts

ReliaQuest says the attackers obtained view-only access to the dashboard, and pointed out that its applications, systems, and customer data were not compromised. The company noted that the threat actor continued with attempts to access applications from the dashboard but was consistently denied due to security controls in place.

In a follow-up statement, ReliaQuest added: “No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established. Claims that ReliaQuest was compromised or targeted by ransomware are false.”

ShinyHunters' Expanding Tactics

The incident highlights ShinyHunters' evolving social engineering playbook. The group has been known for large-scale data breaches and credential theft, but this campaign demonstrates a focus on targeted phishing that exploits trust in internal communications. The use of 'company.claims' domains suggests a broader pattern of impersonation against multiple organizations.

ReliaQuest's earlier warning about the campaign noted that the gang has been expanding its tactics to include legal team impersonation. This shift underscores the increasing sophistication of social engineering attacks, which often bypass technical controls by targeting human vulnerabilities.

Response and Mitigation

In response to the incident, ReliaQuest said it contained the breach promptly. The company did not disclose specific security measures taken but reiterated that its security controls prevented further access. It also stated that the incident was isolated and that no customer data was exposed.

For other organizations, the incident serves as a reminder of the importance of multi-factor authentication and employee training. Even a single credential compromise can grant attackers a foothold, though strong controls can limit the damage.

Why It Matters

This incident illustrates that even security vendors can be targeted and that social engineering remains a potent threat. The fact that a single employee's action led to a brief access session, but was contained, highlights the value of layered security. For businesses, it suggests that while no defense is perfect, rapid detection and response can prevent a minor incident from becoming a major breach.

#shinyhunters#social engineering#reliaquest#okta#phishing#breach

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories