"The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched," ReliaQuest said in a weekend statement.
ReliaQuest confirms a social‑engineering hit and rapid containment
ReliaQuest, a cybersecurity company, acknowledged that one of its employees was targeted in a social‑engineering campaign after attackers impersonated a member of the company’s security team. According to the company’s statement, an attacker called multiple employees and tried to trick them into using "a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."
ReliaQuest reported that one employee entered credentials on the counterfeit SSO page and approved a multi‑factor authentication (MFA) push, which granted the attacker temporary, view‑only access to the firm's identity dashboard. The company says it terminated the attacker’s sessions, revoked the exposed password, and reset all authentication tokens. An internal investigation, ReliaQuest reported, found no evidence the actor accessed other accounts, applications, or data, and no signs that persistence was established on ReliaQuest’s systems.
The .claims lookalike domain and the mechanics of the lure
Researchers and reporting linked the phish page to a "lookalike domain" identified by BleepingComputer as reliaquest.claims. ReliaQuest’s Threat Research team had earlier shared — in a post later deleted — that the ShinyHunters extortion gang was registering .claims domains to impersonate help desks and IT teams. "ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern," the company wrote, adding that those domains "incorporate the targeted organization’s name or abbreviation under the .claims TLD."
The attackers also used the name of a real security employee during vishing attempts, according to the company. One of the targeted employees accepted the ruse and completed the login sequence on the fake SSO page.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOkta SSO, the MFA push, and device‑trust protections
The evidence shown publicly by the actor included screenshots that appeared to show a compromised Okta SSO account for a ReliaQuest employee. After the victim approved the MFA prompt, the threat actor gained temporary, view‑only visibility in the identity dashboard. ReliaQuest reported that device‑trust controls then blocked subsequent attempts to access applications through the dashboard.
"The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place," the company said, and it reported auditing its control fidelity, device trust, and on‑network access since August 21 without identifying suspicious activity.
ShinyHunters published screenshots and claimed the incident
Shortly after ReliaQuest’s posts, a newly‑created X account believed to be linked to ShinyHunters replied to the company thread, writing "Who's hunting who ?" and sharing screenshots. The screenshots were later published by ShinyHunters on its data leak site in a new entry. Both ReliaQuest’s and the alleged threat actor’s posts were subsequently taken down from X.
ReliaQuest’s public statement came after ShinyHunters posted on its extortion portal, referencing ReliaQuest’s earlier reporting on the group and saying "this time the post is about you, not us." When BleepingComputer asked whether the disclosed incident is linked to ShinyHunters, ReliaQuest had not provided additional information at the time of reporting. ShinyHunters told BleepingComputer that its access was view‑only and "did not reach any applications, systems, or customer data," adding: "No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established."
What this means for technologists, enterprises, and end users
- Technologists and security teams: The episode highlights how a single successful social‑engineering call plus an MFA approval can yield dashboard visibility. ReliaQuest’s experience shows device‑trust controls and rapid session revocation can limit follow‑on impact — but the initial credential capture did permit temporary access to an identity console.
- Enterprises and procurement leaders: The appearance of lookalike .claims domains that incorporate organizational names underscores the need to monitor domain registrations tied to corporate brands and help‑desk impersonation tactics; ReliaQuest identified reliaquest.claims as the lookalike used in this incident.
- End users: The attack combined vishing (voice‑based social engineering) and a convincing fake SSO page; one employee entering credentials and approving an MFA push was sufficient to produce temporary, view‑only access to the identity dashboard.
ReliaQuest says it took immediate corrective steps — terminating sessions, revoking the exposed password, and resetting authentication tokens — and found no signs of broader compromise following its audit through August 21. The company and reporters alike left open the degree to which the incident is tied to the ShinyHunters extortion group; ShinyHunters has publicly claimed the event and provided the screenshots it says prove access, while ReliaQuest has described the extent of the access as view‑only and reported no customer data was touched.
Source: BleepingComputer — ReliaQuest confirms failed data‑theft attack after ShinyHunters breach




