ReliaQuest Falls Victim to Elaborate Social Engineering Attack, but Security Measures Keep Breach at Bay
A sophisticated social engineering attack has targeted cybersecurity firm ReliaQuest, with hackers impersonating a member of the security team to trick employees into accessing a fake single sign-on (SSO) page. Although the attackers were able to gain temporary access to one employee’s identity dashboard, the company’s robust security measures prevented them from breaching any applications or customer data.
The attack, which was linked to the notorious ShinyHunters extortion gang, began with phishing attempts on multiple employees. The hackers used a “lookalike domain” – reliaquest.claims – and claimed to be a member of ReliaQuest’s security team. One employee fell for the ruse and entered their credentials on the fake SSO page, allowing the attacker temporary view-only access to the identity dashboard.
However, device-trust controls kicked in, blocking subsequent attempts by the attacker to access applications through the dashboard. The company quickly terminated the attacker’s sessions, revoked the exposed password, and reset all authentication tokens. An investigation found no evidence of access to other accounts, apps, or data, and no signs that the actor established persistence on ReliaQuest’s systems.
ReliaQuest’s security measures were put to the test in this incident, but ultimately proved effective in preventing a full-blown breach. The company audited its control fidelity, device trust, and on-network access since August 21 and identified no suspicious activity. This highlights the importance of robust security controls and regular audits in detecting and preventing breaches.
The ShinyHunters gang has been making headlines recently for their data extortion attacks, and this incident suggests that they may be using increasingly sophisticated tactics to gain access to sensitive information. However, ReliaQuest’s swift response and robust security measures have prevented any significant damage or data loss.
As the threat landscape continues to evolve, it’s essential for companies to stay vigilant and invest in robust security measures. This incident serves as a reminder that even with the best defenses, attackers can still find ways to gain access to sensitive information if employees are tricked into revealing their credentials.
For individuals, this highlights the importance of being cautious when receiving unsolicited calls or emails from supposed security team members. Always verify the authenticity of requests and be wary of phishing attempts that try to manipulate you into accessing fake pages or revealing sensitive information. By staying informed and vigilant, we can all play a role in preventing these types of attacks and protecting our sensitive data.
Source: Bleeping Computer — 2026-08-24