ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Cybersecurity firm ReliaQuest confirms social engineering attack linked to ShinyHunters extortion group

ReliaQuest, a cybersecurity company, has confirmed that an attacker gained brief, view-only access to an employee’s identity dashboard after a social engineering campaign tricked one staff member into entering credentials on a fraudulent login page. The company said its device-trust protections blocked the intruder from reaching any further systems.


The incident traces back to August 17, when ReliaQuest’s Threat Research team posted on X that it was monitoring a broad campaign by the extortion group ShinyHunters. According to that post, the group was registering domains that followed a "company[.]claims" pattern, inserting a target organization’s name or abbreviation ahead of the ".claims" domain suffix. ReliaQuest also warned in the post that the group had broadened its impersonation tactics beyond IT and help desk personnel to include legal team impersonation. That post was later removed from X.


An attacker then called several ReliaQuest employees directly, posing each time as a named member of the company’s own security staff, and attempted to direct them to a fraudulent single sign-on page built to mimic ReliaQuest’s login system. Sources told BleepingComputer the lookalike domain used in the scheme was reliaquest.claims, hosted behind a content delivery network.


One employee entered login credentials on the fake page and approved a multifactor authentication push notification, granting the attacker a short-lived, view-only session on ReliaQuest’s identity dashboard. The company said repeated attempts by the attacker to move from that dashboard into other applications were blocked by its security controls. "The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched," the company said. "The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place."


ReliaQuest said it terminated the attacker’s active sessions, revoked the compromised password and reset authentication tokens across its systems. A subsequent internal review turned up no indication that the intruder reached other accounts, applications or data, and no sign that the attacker established lasting access. The company also reviewed its control performance, device-trust systems and network activity dating back to August 21 and reported no additional suspicious behavior.


A newly created X account believed to be tied to the attackers responded to ReliaQuest’s original warning with the message "Who’s hunting who?" alongside screenshots purporting to show access to a ReliaQuest Okta single sign-on account. The same images later appeared on ShinyHunters’ data leak site, where the group added a message referencing ReliaQuest’s earlier reporting on the gang: "this time the post is about you, not us." Both the account’s reply and ReliaQuest’s original post were subsequently taken down from X.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543