ReliaQuest confirmed that one employee was targeted in a social engineering attack involving a fake SSO page, with the attacker using a lookalike .claims domain and vishing tactics. The company says the incident was contained with no customer data accessed, while ShinyHunters publicly claimed the attack and posted evidence of access to a ReliaQuest Okta SSO account. #ReliaQuest #ShinyHunters #Okta
Keypoints
- ReliaQuest detected a social engineering attack against one employee.
- The attacker impersonated a security team member and used a fake SSO page.
- The phishing site used a lookalike .claims domain tied to ReliaQuest.
- One victim entered credentials and approved an MFA push notification.
- ReliaQuest contained the incident and found no access to customer data or systems.