The ShinyHunters ReliaQuest phishing attack has now been confirmed by the company itself, with ReliaQuest acknowledging that one of its employees fell for a voice phishing (vishing) and fake SSO page combination, while insisting that no applications, systems, or customer data were ever reached. The whole episode has the peculiar quality of a cybersecurity firm being caught out by a campaign it had itself been publicly tracking.
How the ShinyHunters ReliaQuest phishing attack unfolded
According to ReliaQuest, an attacker called multiple employees and attempted to trick them into visiting a fake ReliaQuest single sign-on (SSO) page hosted behind a content delivery network. The phishing page was served from a lookalike domain that BleepingComputer learned from sources was reliaquest.claims, fitting squarely into the company.claims URL pattern that ReliaQuest had itself flagged. The attacker also used the name of a real ReliaQuest security employee during the calls to add credibility.
One targeted employee entered their credentials on the fake page and then approved a multi-factor authentication (MFA) push notification, granting the attacker temporary, view-only access to ReliaQuest’s identity dashboard. Device-trust controls then kicked in, consistently blocking any subsequent attempts to reach applications through that dashboard.
‘The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched,’ the company said. ‘The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.’
ReliaQuest says it terminated the attacker’s sessions, revoked the compromised password, and reset all authentication tokens. A subsequent investigation found no evidence of access to other accounts, apps, or data, and no signs the actor established persistence. The firm audited its control fidelity, device trust, and on-network access since 21 August and identified no suspicious activity.
A timeline with some irony built in
The backstory here is hard to miss. On 17 August, ReliaQuest had posted on X that it was tracking a widespread ShinyHunters campaign using domains following the company.claims pattern, incorporating a targeted organisation’s name or abbreviation under the .claims TLD, SecurityWeek reports. That post has since been deleted.
ShinyHunters apparently noticed. A newly-created X account believed to be linked to the threat actors replied to ReliaQuest’s post with ‘Who’s hunting who?’, along with screenshots of what appeared to be a compromised Okta SSO account belonging to a ReliaQuest employee. ShinyHunters then published the same screenshots on its data leak site. Both posts were subsequently taken down from X.
According to The Register, ShinyHunters listed ReliaQuest on its leak site on 23 August, framing the post as payback for the firm’s earlier reporting: ‘this time the post is about you, not us.’ ReliaQuest confirmed the attack took place on 22 August, disputing the suggestion that ShinyHunters had compromised its systems in any meaningful sense.
ShinyHunters’ own account to BleepingComputer broadly aligns with ReliaQuest’s version. ‘No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established,’ the threat actor said, which is a fairly unusual situation where attacker and victim largely agree on the scope of the damage.
The broader ShinyHunters campaign
The ShinyHunters ReliaQuest phishing attack did not appear from nowhere. The group’s company.claims campaign is designed to impersonate corporate help desks and IT teams at scale, using domains that swap in the target organisation’s name or abbreviation before the .claims TLD. ReliaQuest’s own Threat Research team had been documenting it, which makes the firm’s subsequent appearance on the leak site all the more pointed.
The vishing layer is particularly worth noting. Calling employees, impersonating known internal personnel by name, and then directing targets to a CDN-hosted phishing page is a more involved operation than a mass-phishing email blast. MFA push fatigue and social pressure combined to get one credential set compromised. The device-trust layer is what prevented that from translating into anything worse.
ReliaQuest says it has not attributed the incident publicly to ShinyHunters, and BleepingComputer had not received a response to that specific question at the time of reporting. The company’s investigation into the ShinyHunters ReliaQuest phishing attack is ongoing, and ReliaQuest has committed to sharing further technical details about the campaign’s tactics, techniques, and procedures.

