Zero Day Room
Live
Threats

ReliaQuest Targeted by ShinyHunters Hackers

Threats: Team of cyber security experts working on laptops in a vibrant neon-lit room

ReliaQuest, a cybersecurity firm, has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group.

The hackers, who have been expanding their social engineering tactics to include legal team impersonation alongside IT and help desk impersonation, targeted ReliaQuest in a social engineering attack over the weekend.

According to ReliaQuest, the hackers registered a fake domain and set it up to host a ReliaQuest SSO phishing page.

The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page.

One teammate entered their password and approved the push notification on their phone, handing the attacker a brief session on the identity dashboard.

ReliaQuest says the attackers obtained view-only access to the dashboard, but were consistently denied access to the company's applications, systems, and customer data due to the security controls in place.

The company claims that no additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established.

ReliaQuest has denied claims that the company was compromised or targeted by ransomware, stating that these claims are false.

The incident was first reported on ReliaQuest's X account on August 17, but the post has since been deleted.

The same screenshots were posted on ShinyHunters' website, along with a message taunting the security firm.

ReliaQuest addressed the incident on Monday, admitting it had been targeted in a social engineering attack.

The company has not disclosed the exact number of teammates who were targeted by the hackers or the extent of the damage caused by the attack.

The incident highlights the growing threat of social engineering attacks, which can be particularly effective in targeting employees who are unaware of the tactics used by hackers.

ReliaQuest's security controls in place prevented the attackers from accessing sensitive data, but the incident serves as a reminder of the importance of employee education and awareness in preventing such attacks.

The company's response to the incident has been met with skepticism by some, who claim that the impact of the attack was more significant than ReliaQuest is letting on.

However, ReliaQuest maintains that the impact of the attack was limited, and that the company's security controls prevented any significant damage.

The incident is a reminder of the ongoing threat of cyber attacks and the importance of robust security controls in preventing such attacks.

The company's statement on the incident can be found on its website.

The incident has been reported on SecurityWeek, a leading cybersecurity news website.

According to SecurityWeek, ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the 'company.claims' URL pattern.

The incident is a reminder of the importance of employee education and awareness in preventing social engineering attacks.

The company's security controls in place prevented the attackers from accessing sensitive data, but the incident serves as a reminder of the ongoing threat of cyber attacks.

The company's statement on the incident can be found on its website.

The incident has been reported on SecurityWeek, a leading cybersecurity news website.

Related coverage

More from Threats