Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » ShinyHunters ReliaQuest Phishing Attack Confirmed, But Firm Says Nothing Was Taken
    Technology

    ShinyHunters ReliaQuest Phishing Attack Confirmed, But Firm Says Nothing Was Taken

    Gary BehanBy Gary Behan29/08/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    ShinyHunters ReliaQuest phishing attack
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    The ShinyHunters ReliaQuest phishing attack has now been confirmed by the company itself, with ReliaQuest acknowledging that one of its employees fell for a voice phishing (vishing) and fake SSO page combination, while insisting that no applications, systems, or customer data were ever reached. The whole episode has the peculiar quality of a cybersecurity firm being caught out by a campaign it had itself been publicly tracking.

    How the ShinyHunters ReliaQuest phishing attack unfolded

    According to ReliaQuest, an attacker called multiple employees and attempted to trick them into visiting a fake ReliaQuest single sign-on (SSO) page hosted behind a content delivery network. The phishing page was served from a lookalike domain that BleepingComputer learned from sources was reliaquest.claims, fitting squarely into the company.claims URL pattern that ReliaQuest had itself flagged. The attacker also used the name of a real ReliaQuest security employee during the calls to add credibility.

    One targeted employee entered their credentials on the fake page and then approved a multi-factor authentication (MFA) push notification, granting the attacker temporary, view-only access to ReliaQuest’s identity dashboard. Device-trust controls then kicked in, consistently blocking any subsequent attempts to reach applications through that dashboard.

    ‘The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched,’ the company said. ‘The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.’

    ReliaQuest says it terminated the attacker’s sessions, revoked the compromised password, and reset all authentication tokens. A subsequent investigation found no evidence of access to other accounts, apps, or data, and no signs the actor established persistence. The firm audited its control fidelity, device trust, and on-network access since 21 August and identified no suspicious activity.

    A timeline with some irony built in

    The backstory here is hard to miss. On 17 August, ReliaQuest had posted on X that it was tracking a widespread ShinyHunters campaign using domains following the company.claims pattern, incorporating a targeted organisation’s name or abbreviation under the .claims TLD, SecurityWeek reports. That post has since been deleted.

    ShinyHunters apparently noticed. A newly-created X account believed to be linked to the threat actors replied to ReliaQuest’s post with ‘Who’s hunting who?’, along with screenshots of what appeared to be a compromised Okta SSO account belonging to a ReliaQuest employee. ShinyHunters then published the same screenshots on its data leak site. Both posts were subsequently taken down from X.

    According to The Register, ShinyHunters listed ReliaQuest on its leak site on 23 August, framing the post as payback for the firm’s earlier reporting: ‘this time the post is about you, not us.’ ReliaQuest confirmed the attack took place on 22 August, disputing the suggestion that ShinyHunters had compromised its systems in any meaningful sense.

    ShinyHunters’ own account to BleepingComputer broadly aligns with ReliaQuest’s version. ‘No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established,’ the threat actor said, which is a fairly unusual situation where attacker and victim largely agree on the scope of the damage.

    The broader ShinyHunters campaign

    The ShinyHunters ReliaQuest phishing attack did not appear from nowhere. The group’s company.claims campaign is designed to impersonate corporate help desks and IT teams at scale, using domains that swap in the target organisation’s name or abbreviation before the .claims TLD. ReliaQuest’s own Threat Research team had been documenting it, which makes the firm’s subsequent appearance on the leak site all the more pointed.

    The vishing layer is particularly worth noting. Calling employees, impersonating known internal personnel by name, and then directing targets to a CDN-hosted phishing page is a more involved operation than a mass-phishing email blast. MFA push fatigue and social pressure combined to get one credential set compromised. The device-trust layer is what prevented that from translating into anything worse.

    ReliaQuest says it has not attributed the incident publicly to ShinyHunters, and BleepingComputer had not received a response to that specific question at the time of reporting. The company’s investigation into the ShinyHunters ReliaQuest phishing attack is ongoing, and ReliaQuest has committed to sharing further technical details about the campaign’s tactics, techniques, and procedures.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleZimbra CVE-2026-73570 CISA patch deadline hits as compromised servers climb past 270
    Next Article Calix GigaSpire UPnP vulnerability leaves home networks open with no patch in sight
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Zimbra CVE-2026-73570 Attacks Breach Hundreds of Servers Globally

    29/08/2026

    Calix GigaSpire UPnP vulnerability leaves home networks open with no patch in sight

    29/08/2026

    Zimbra CVE-2026-73570 CISA patch deadline hits as compromised servers climb past 270

    28/08/2026

    ToxicPanda Android Malware VPN Trick Now Targets 349 Banking Apps

    28/08/2026

    Android car head unit malware hijacks update app to build proxy botnet

    28/08/2026

    SynkLoader Microsoft Teams Phishing Campaign Deploys Fake Lock Screen and RAT

    27/08/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.