ReliaQuest confirmed it was targeted by the ShinyHunters group in a social engineering attack that used a fake domain and phishing page to steal a teammate’s credentials. The company said the incident was contained, with only brief view-only access to an identity dashboard and no compromise of customer data or business systems. #ReliaQuest #ShinyHunters #Okta
Keypoints
- ReliaQuest was targeted by hackers linked to ShinyHunters.
- The attackers used a phishing campaign with domains following a company.claims pattern.
- ShinyHunters expanded impersonation tactics to include legal team roles.
- A fake ReliaQuest SSO page was used to trick a teammate into entering credentials and approving MFA.
- ReliaQuest says only brief view-only dashboard access was gained and no customer data or systems were compromised.
Read More: https://www.securityweek.com/reliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited/