ShinyHunters phishing call fails to breach ReliaQuest

Published August 24, 2026

Attackers linked to the ShinyHunters extortion group called ReliaQuest employees, posed as a member of the company's own security team, and sent them to a fake login page to steal credentials. One employee typed in their password and approved a login prompt, but ReliaQuest's security controls stopped the attackers from actually reaching data or systems.

Report priority
Medium
Targets
Android+1 more

How it works

  • Attackers called ReliaQuest staff by phone, pretended to be a real internal security employee, and directed them to a lookalike login page called reliaquest.claims that mimicked the company's real single sign-on page.
  • One employee entered their password there and approved a push notification asking to confirm the login, which handed the attacker a...

What to do

ReliaQuest says it shut down the attacker's session, reset the stolen password, revoked all authentication tokens, and found no evidence the attacker reached customer data or other accounts. Anyone who gets a call from someone claiming to be their company's security team should hang up and verify through a known internal channel before entering credentials anywhere.

Technical details

Affected software: Android, Windows

An attacker cold-calls a ReliaQuest employee and claims to be a named member of the company's own security team. The employee is guided to reliaquest.claims, a fake copy of ReliaQuest's single sign-on page, and types in their username and password. The attacker also gets the employee to approve a multi-factor login prompt, which opens a view-only session in the identity dashboard, but device-trust checks then block every attempt to go further into real company applications.

The threat actor ran a vishing (voice phishing) campaign registering lookalike domains under the.claims top-level domain named after target companies, matching a pattern ReliaQuest's own threat research team had flagged before being targeted itself. The phishing infrastructure sat behind a content delivery network. A ReliaQuest employee authenticated to reliaquest.claims and approved an MFA push, giving the attacker a session token good for view-only access to the company's Okta-based identity dashboard. Device-trust posture checks then denied all subsequent attempts to pivot from that dashboard into actual applications, containing the intrusion before any data access occurred.