
Cybersecurity company ReliaQuest confirmed over the weekend that the ShinyHunters extortion group successfully tricked one of its employees into entering credentials on a fake single sign-on (SSO) login page — but that device-trust controls ultimately blocked any real damage. The attackers called multiple ReliaQuest employees while impersonating a member of the company’s own security team, directing them to a lookalike domain (reportedly reliaquest.claims) built to mirror the company’s Okta SSO portal. One employee entered their credentials and approved an MFA push notification, giving the attackers temporary, view-only access to ReliaQuest’s identity dashboard. When they then tried to use that access to log into ReliaQuest’s applications, device-trust checks denied every attempt because the request came from an untrusted machine.
The attack follows a pattern ReliaQuest itself had publicly documented just days earlier: ShinyHunters has been registering .claims domains that match company names (e.g., company.claims) to set up convincing IT help-desk impersonation campaigns. The irony of a cybersecurity company falling for a technique it had just published research on underscores how effective vishing combined with realistic phishing portals can be. ReliaQuest said the attacker gained “view-only” access and never touched any customer data or company applications; the company terminated the session, revoked the exposed credentials, and found no signs of persistence after a full audit. ShinyHunters subsequently posted about the attack on their data-leak site, sharing screenshots of the compromised identity dashboard, before both parties deleted their public posts. The incident is a reminder that even organizations with strong security controls can have individual employees fall for well-executed social engineering — and that layered defenses like device-trust policies are what prevent a credential theft from becoming a breach.
