Skip to content
Tech News
← Back to articles

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

read original more articles
Why This Matters

This incident highlights the ongoing threat of social engineering and phishing attacks targeting cybersecurity firms, emphasizing the importance of robust security measures and employee training. It underscores the need for organizations to remain vigilant against sophisticated impersonation tactics that can compromise internal systems, even in highly secure environments.

Key Takeaways

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team.

In a statement over the weekend, ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing "a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."

Last week, ReliaQuest's Threat Research team shared in a now-deleted post, that the ShinyHunters extortion gang was registering .claims domains to impersonate company's help desks and IT teams.

"ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization’s name or abbreviation under the .claims TLD," read the company's post on X.

Yesterday, a newly-created X account believed to be linked to the threat actors replied to the post, stating "Who's hunting who ?," sharing screenshots of what appeared to be a compromised Okta SSO account for a ReliaQuest employee.

Soon after, ShinyHunters published the same screenshots in a new entry on their data data leak site.

Both ReliaQuest's and the alleged threat actor's posts were later taken down from X.

According to the company, the threat actor hosted the phishing page on a "lookalike domain," which BleepingComputer learned from sources was reliaquest.claims, and used the name of a real security employee during the vishing attempts.

... continue reading