ReliaQuest Confirms Targeting by ShinyHunters in Limited Social Engineering Attack

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited.

ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the ‘company.claims’ URL pattern. The company also warned that the hacker gang has been expanding its social engineering tactics to include legal team impersonation alongside IT and help desk impersonation.

In response to that now-deleted post, someone shared several screenshots that appeared to show access to a ReliaQuest Okta dashboard. The same screenshots were posted on ShinyHunters’ website, along with a message taunting the security firm.

Incident Overview

ReliaQuest addressed the incident on Monday, admitting it had been targeted in a social engineering attack over the weekend. According to the company, the hackers registered a fake domain and set it up to host a ReliaQuest SSO phishing page. “The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page,” the security firm explained. “One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”

Impact and Response

ReliaQuest says the attackers obtained view-only access to the dashboard, and pointed out that its applications, systems, and customer data were not compromised. “The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place,” it noted. ReliaQuest added, “No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established. Claims that ReliaQuest was compromised or targeted by ransomware are false.”

For further details, refer to the report by SecurityWeek.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Supply Chain Attacks Target Developer Tools and CI/CD Pipelines, Research Reveals

In recent years, supply chain attacks have evolved dramatically, shifting from targeting finished software to infiltrating the very tools and code that developers use...

NordVPN Alerts Android Users to Malware Posing as Ryanair, Emirates, and Qatar Airways Apps

NordVPN has issued a warning to Android users about a sophisticated malware campaign that impersonates over 65 well-known brands, including Ryanair, Emirates, and Qatar...

AliExpress Exposed for Using Inaudible Sounds to Fingerprint Browser Visitors

AliExpress has come under scrutiny for employing an outdated method of browser fingerprinting that utilizes inaudible sounds to track visitors. This technique, which exploits...

U.S. Postal Service Finalizes Mail-in Ballot Regulations Amid Supreme Court Appeal

The U.S. Postal Service (USPS) has announced the finalization of new regulations that could grant the federal government significant control over mail-in ballots for...