Tech News
← Home  ·  All topics

Reliaquest

2 GoKawiil briefs on this topic

ShinyHunters' claimed ReliaQuest breach limited to view-only SSO access

Threat group ShinyHunters publicly taunted security vendor ReliaQuest, posting screenshots suggesting a compromised employee account and listing the company on its data leak site. ReliaQuest confirmed an employee was tricked via a vishing attack into entering credentials on a fake single sign-on page, but said the attacker only gained view-only access and could not move laterally or reach internal applications.

ReliaQuest says ShinyHunters phishing attempt was blocked before data access

ReliaQuest confirmed that ShinyHunters attackers impersonated its own security staff in vishing calls, directing an employee to a fake single sign-on page hosted on a lookalike domain, reliaquest.claims. The employee entered credentials and approved an MFA prompt, giving attackers brief, view-only access to an identity dashboard, but device-trust controls stopped further access to systems or customer data.