Cybersecurity company ReliaQuest confirmed that one of its employees was targeted in a social engineering attack in which the attackers impersonated a member of the security team, but their attempt to access the company’s systems and data was unsuccessful. The company explained that the attackers made phone calls to several employees and attempted to direct them to a fake single sign-on (SSO) login page hosted behind a content delivery network.
The incident began after ReliaQuest’s Threat Research Unit warned of a campaign attributed to the extortion group ShinyHunters. The campaign relies on registering domains under the .claims top-level domain and creating addresses resembling the help desk and IT team domains of targeted organizations. The company said the domains follow a pattern that includes the organization’s name or abbreviation before the extension, while BleepingComputer sources identified the domain used in this incident as reliaquest.claims.
Temporary Access Without Reaching Applications
One targeted employee successfully entered their credentials on the fake SSO page and also approved a multifactor authentication notification on their phone. This gave the attacker temporary read-only access to ReliaQuest’s identity dashboard, and the attacker appears to have used the name of a real security team employee during the voice-phishing calls.
However, the access did not develop into a broader compromise. The company said device trust controls blocked subsequent attempts to access applications through the identity dashboard, and the attacker continued to receive denials when attempting to use those applications. According to ReliaQuest, none of its applications or systems were accessed, and customer data was not affected.
The company terminated the attacker’s sessions, revoked the exposed password, and reset all authentication tokens. It also reviewed the enforcement of access controls, device trust, and internal network access since August 21, saying the investigation found no evidence of access to other accounts, applications, or data, or of the attacker establishing a persistence mechanism within its systems.
What Does This Incident Demonstrate in Practice?
The incident shows that successful phishing, credential theft, and approval of an MFA request do not automatically mean that an attacker can access an organization’s resources. In this case, a subsequent layer of controls stopped attempts originating from a device or context that did not meet the trust requirements. This interpretation is based on the incident sequence as described by ReliaQuest and is not evidence that multifactor authentication alone prevented the compromise.
ShinyHunters published screenshots that it said proved the compromise of an Okta SSO account belonging to a ReliaQuest employee, then included the screenshots on its data leak site. In a post, the group referred to previous ReliaQuest reports about it and also told BleepingComputer that its access was read-only and did not reach applications, systems, or customer data. However, ReliaQuest did not additionally confirm that ShinyHunters was the party that carried out the attack, so attribution of the incident to the group remains an unresolved claim in the available information.