ShinyHunters Targets ReliaQuest in Sophisticated Social Engineering Attack
Cybersecurity firm **ReliaQuest** recently confirmed a social engineering attack orchestrated by the notorious **ShinyHunters** extortion group. Attackers impersonated security personnel to trick an employee into providing credentials, gaining temporary, view-only access to an identity dashboard before being thwarted by robust security controls.

Cybersecurity company **ReliaQuest** has confirmed that one of its employees was targeted in a sophisticated social engineering attack, where hackers impersonated a member of the security team.
In a statement over the weekend, **ReliaQuest** detailed how an attacker called multiple employees, attempting to trick them into accessing "a fake **ReliaQuest** single sign-on (**SSO**) page behind a content delivery network."
Last week, **ReliaQuest**'s Threat Research team had already highlighted a **ShinyHunters** campaign, noting the group's registration of `.claims` domains to impersonate company help desks and IT teams.
"**ReliaQuest** is tracking a widespread **ShinyHunters** campaign using domains that follow the company\[.\]claims pattern. These domains incorporate the targeted organizationβs name or abbreviation under the .claims TLD," read the company's prior post on X.
### The Attack Unfolds
An account believed to be linked to the threat actors replied to **ReliaQuest**'s warning post, stating "Who's hunting who ?," and sharing screenshots that appeared to show a compromised **Okta SSO** account for a **ReliaQuest** employee. Soon after, **ShinyHunters** published these same screenshots on their data leak site. Both **ReliaQuest**'s and the alleged threat actor's posts were subsequently removed from X.
According to **ReliaQuest**, the threat actor hosted the phishing page on a "lookalike domain," which sources confirmed was `reliaquest.claims`, and used the name of a real security employee during the vishing attempts.
One targeted employee fell for the ruse, entering their credentials on the fake **SSO** page and approving a Multi-Factor Authentication (**MFA**) push notification. This action granted the attacker temporary, view-only access to **ReliaQuest**'s identity dashboard.
However, device-trust controls successfully blocked subsequent attempts to access applications through the dashboard.
βThe extent of the access was view-only. No **ReliaQuest** applications or systems were accessed, and no customer data was ever touched,β **ReliaQuest** stated. βThe threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.β
### Swift Response and Investigation
The cybersecurity firm swiftly terminated the attackerβs sessions, revoked the exposed password, and reset all authentication tokens. An ensuing investigation found no evidence of access to other accounts, applications, or data, and no signs that the actor established persistence on **ReliaQuest**βs systems.
**ReliaQuest** audited its control fidelity, device trust, and on-network access since August 21 and identified no suspicious activity.
### ShinyHunters Claims Responsibility
**ReliaQuest**βs statement comes shortly after the infamous data extortion group **ShinyHunters** publicly claimed responsibility for an attack on the company. In a new post on its extortion portal, **ShinyHunters** provocatively referenced **ReliaQuest**βs previous reporting on the group, stating, "this time the post is about _you_, not us."

_**ReliaQuest** listed on the **ShinyHunters** extortion page_
The threat actors published evidence of access, demonstrating they had successfully breached a **ReliaQuest Okta SSO** account. While **ReliaQuest** has not explicitly linked the incident to **ShinyHunters** in their public statement, **ShinyHunters** themselves confirmed to BleepingComputer that their access was indeed view-only and did not extend to applications, systems, or customer data.
"No additional identities were accessed, no business applications were reached, no customer or **ReliaQuest** data was accessed beyond the user's login credentials, and no persistence was established," the threat actor confirmed.