ReliaQuest employee data leaked in ShinyHunters phishing hack
ReliaQuest, a cybersecurity company, says one employee was tricked by a fake login page and briefly gave attackers access to an internal dashboard. The ShinyHunters group only got view-only access and could not reach customer data or other company systems.
- Report priority
- Medium
- Targets
- Okta+1 more
How it works
Attackers built a fake ReliaQuest login page and called employees by phone, naming real security staff to sound convincing, until one employee typed in a password and approved a login prompt on their phone.
What to do
Anyone with questions can review ReliaQuest's own public statement on the incident.
Technical details
Affected software: Okta, ShinyHunters
Attackers register a fake web address built to host a copy of ReliaQuest's login page. They call ReliaQuest employees, naming real security staff by name to steer them toward the fake page. One employee enters their password and approves a push notification on their phone, handing the attacker a short session inside the company's identity dashboard. The attacker tries to use that access to reach other business applications but is blocked each time by ReliaQuest's security controls.
ShinyHunters ran a phone-based social engineering campaign using domains following a company.claims pattern to host fake single sign-on pages. Attackers called ReliaQuest employees, impersonating named security staff to steer them to a fake SSO page for the company's identity provider. One employee entered credentials and approved a push MFA prompt, giving the attacker a session on ReliaQuest's Okta-connected dashboard with view-only access. ReliaQuest says follow-on attempts to reach other business applications from that session were blocked by existing access controls, and no persistence, customer data, or business systems were compromised.