ReliaQuest Failed ShinyHunters Vishing Attack (2026-08-24)
Cybersecurity firm ReliaQuest disclosed a failed data-theft attack by ShinyHunters-linked attackers who vishing-called employees using a lookalike reliaquest.claims SSO page and the name of a real security staff member. One employee surrendered credentials and approved an MFA push, granting temporary view-only access to the identity dashboard โ where device-trust controls blocked every subsequent application access.
Overview
| Attribute | Detail |
|---|---|
| Target | ReliaQuest (cybersecurity firm) |
| Threat actor | ShinyHunters-linked attackers |
| Vector | Vishing with lookalike reliaquest.claims SSO page |
| Status | Probable breach; attack failed โ no data exposure found |
| Date | 2026-08-24 |
What Happened
After the employee approved the MFA push, attackers held view-only access to the Okta identity dashboard but could not reach any applications due to device-trust controls. ReliaQuest terminated sessions, rotated tokens and found no persistence, application access or customer-data exposure. ShinyHunters listed the firm on its leak site and conceded the access was view-only.
Context
The gang had registered .claims impersonation domains that ReliaQuest itself flagged days earlier โ the firm had publicly documented the vishing campaign shortly before being targeted, a reminder that publishing threat intelligence makes you a target for proof-of-work retaliation. This follows Health-ISAC warnings about ShinyHunters targeting healthcare data-theft surface earlier in August.