ReliaQuest has confirmed that a social engineering attack against one of its employees resulted in a failed data-theft attempt, with the company stating that no customer data was accessed. The cybersecurity firm disclosed that an attacker phoned multiple staff members while impersonating a member of the security team, attempting to lure them into entering credentials on a fake ReliaQuest single sign-on page hosted behind a content delivery network. One employee fell for the ruse, submitting their login information and approving a multi-factor authentication push notification, which granted the attacker temporary view-only access to the company’s identity dashboard.
The incident follows ReliaQuest’s own threat research team’s tracking of the ShinyHunters extortion gang, which the company had previously flagged in a now-deleted post for registering domains that follow a company[.]claims pattern to impersonate corporate help desks and IT teams. Shortly after that public warning, a newly created X account believed to be linked to the threat actors replied with a taunt and shared screenshots of what appeared to be a compromised Okta single sign-on account for a ReliaQuest employee. Those same screenshots were then published by ShinyHunters on its data leak site, though both the company’s and the alleged threat actors’ posts were later removed from X.
ReliaQuest says the phishing page was hosted on the lookalike domain reliaquest.claims, and that the attacker used the name of a real security employee during the vishing attempts. Despite the successful credential capture and MFA approval, the company’s device-trust controls blocked subsequent attempts to access applications through the dashboard. According to ReliaQuest, the attacker repeatedly tried to reach these applications but was consistently denied, and the company terminated the sessions, revoked the exposed password, and reset all authentication tokens.
The company’s investigation found no evidence of access to other accounts, applications, or data, and no signs that the attacker established persistence on its systems. ReliaQuest also audited its control fidelity, device trust, and on-network access starting August 21 and found no suspicious activity. The firm emphasized that the access was view-only and that no ReliaQuest applications or systems were reached, nor was any customer data touched.
ShinyHunters, in a post on its extortion portal, referenced ReliaQuest’s earlier reporting on the group and claimed that this time the post concerned the company itself. The threat actors told BleepingComputer that their access was view-only and did not extend to any applications, systems, or customer data, adding that no additional identities were accessed and no persistence was established. TechManNews has not received additional information from ReliaQuest beyond its public statement regarding whether the disclosed incident is directly linked to ShinyHunters.
The episode highlights the risk that valid credentials pose after initial access, even when broader security controls remain in place, particularly for U.S. technology firms using identity platforms like Okta. The company’s response focused on the effectiveness of its device-trust and authentication-token resets in containing the breach. No further details on the attacker’s identity or the source of the phone calls have been disclosed.
More cybersecurity news from TechManNews.






