3 min Security

ShinyHunters strikes at security firm ReliaQuest

ShinyHunters strikes at security firm ReliaQuest

Cybersecurity firm ReliaQuest has itself become the target of a social engineering attack by ShinyHunters. An employee disclosed their login credentials and confirmed an MFA request. The attackers gained access to the identity dashboard, but additional security measures prevented them from accessing company applications or customer data.

BleepingComputer reports that the attack began with phone calls to several employees. The attackers posed as members of ReliaQuest’s security team and attempted to lure their victims to a fake SSO page. To do so, they used a domain that closely resembled the company’s.

One employee followed the instructions and entered their credentials on the fake login page. That employee then also accepted an MFA push notification. This gave the attackers valid authentication credentials to access the employee’s identity dashboard.

There, a subsequent layer of security proved effective. According to ReliaQuest, the access gained was limited to read-only. Controls that verify whether a device is trusted blocked attempts to open other applications from the dashboard.

ReliaQuest terminated the active sessions, invalidated the compromised password, and reset the authentication tokens. According to the company, an investigation into activity since August 21 found no evidence that other accounts or applications were accessed. Nor was there any indication of access to customer data or the creation of a permanent access point.

The incident thus demonstrates that MFA does not necessarily provide sufficient protection against targeted social engineering. When a user personally approves a fraudulent authentication request, additional checks on the device being used can prevent stolen credentials from granting direct access to back-end systems.

ShinyHunters claims responsibility for the attack

ShinyHunters has claimed responsibility for the attack. The extortion group published screenshots purporting to show access to a ReliaQuest Okta account. Notably, the attackers told BleepingComputer they did not gain more than limited access to the account.

ReliaQuest had just warned about a ShinyHunters campaign shortly before this incident. In this campaign, domains are registered that combine a company name or abbreviation with the .claims top-level domain. The sites are used to impersonate help desks and IT departments. According to BleepingComputer sources, the domainreliaquest.claimswas used in the attack on ReliaQuest.

The attackers are also said to have used the name of a real security employee during the phone calls. By combining a credible domain, telephone social engineering, and MFA abuse, they attempted to assume the identity of an employee.

Although ShinyHunters posted evidence of the breach on its own platform, the attempt to actually steal data appears to have failed. Both ReliaQuest and the attackers state that no business applications, internal data, or customer information were compromised.