One approved push notification let vishers into ReliaQuest

One approved MFA push gave ShinyHunters-linked callers a brief view-only session inside ReliaQuest.

CSBadmin
2 Min Read

A single approved push notification gave ShinyHunters-affiliated attackers a foothold inside ReliaQuest, a security firm that had been publicly tracking the gang days earlier.

The company acknowledged the intrusion on August 22. Attackers built a lookalike domain and a fake single sign-on page, parked it behind a content delivery network, and phoned employees while posing as named security-team members. One worker typed in a password and accepted the MFA push, giving the callers a short-lived view-only session in the identity dashboard.

The firm says no applications or systems were reached, no customer data was touched, and repeated attempts to pivot from the dashboard were denied. Its defense rested on device trust: logging into the identity system did not grant access to everything else, and untrusted devices could not reach corporate applications even with valid credentials. ReliaQuest terminated the session, forced a password reset, and reset every authentication factor on the account.

ShinyHunters tells a different story, posting screenshots that appear to show an Okta SSO account and taunting the researchers with “Who’s hunting who?” A listing naming ReliaQuest appeared on a leak site on August 23.

The episode began when ReliaQuest warned about the group’s use of company-named .claims domains and its impersonation of legal, help desk, and IT staff. Its own account of the breach ends with a blunt note: phishing works, even against trained staff.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.