Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [incident, shinyhunters, vishing, social-engineering, okta, device-trust, probable-breach, phishing] ยท confidence: high ยท affected_sectors: [professional-services, technology] ยท au_impact: false

ReliaQuest Failed ShinyHunters Vishing Attack (2026-08-24)

Cybersecurity firm ReliaQuest disclosed a failed data-theft attack by ShinyHunters-linked attackers who vishing-called employees using a lookalike reliaquest.claims SSO page and the name of a real security staff member. One employee surrendered credentials and approved an MFA push, granting temporary view-only access to the identity dashboard โ€” where device-trust controls blocked every subsequent application access.

Overview

Attribute Detail
Target ReliaQuest (cybersecurity firm)
Threat actor ShinyHunters-linked attackers
Vector Vishing with lookalike reliaquest.claims SSO page
Status Probable breach; attack failed โ€” no data exposure found
Date 2026-08-24

What Happened

After the employee approved the MFA push, attackers held view-only access to the Okta identity dashboard but could not reach any applications due to device-trust controls. ReliaQuest terminated sessions, rotated tokens and found no persistence, application access or customer-data exposure. ShinyHunters listed the firm on its leak site and conceded the access was view-only.

Context

The gang had registered .claims impersonation domains that ReliaQuest itself flagged days earlier โ€” the firm had publicly documented the vishing campaign shortly before being targeted, a reminder that publishing threat intelligence makes you a target for proof-of-work retaliation. This follows Health-ISAC warnings about ShinyHunters targeting healthcare data-theft surface earlier in August.

Source