ShinyHunters phoned a ReliaQuest employee, and one of them fell for it
The security firm says a vishing call led to a view-only peek at its Okta dashboard, but device-trust rules stopped anything worse.

Key points
- ReliaQuest confirmed over the weekend that an employee was tricked by a phone-based phishing call and entered credentials into a fake single sign-on page at reliaquest.claims.
- The attacker, linked to the extortion group ShinyHunters, gained view-only access to ReliaQuest's Okta identity dashboard after the employee approved a multi-factor prompt.
- Device-trust controls blocked every attempt to open actual applications from that dashboard, and ReliaQuest says no customer data was touched.
- ShinyHunters published screenshots on its leak site and taunted ReliaQuest on X after the security firm had earlier flagged the group's use of company[.]claims lookalike domains.
- ReliaQuest revoked the exposed password, killed the attacker's sessions, and reset authentication tokens; an audit going back to 21 August found no other suspicious activity.
Cybersecurity firm ReliaQuest has admitted that one of its own staff was fooled by a phone scam, in an incident the extortion crew ShinyHunters is loudly claiming as a win.
The attackers called multiple ReliaQuest employees pretending to be a member of the internal security team, using a real employee's name to sound credible. Victims were directed to a fake single sign-on page, the one company portal staff use to reach all their work tools, hosted behind a content delivery network to make the address look less suspicious.
One employee bit. They typed their password into the fake page and approved the multi-factor push notification that landed on their phone, handing the caller a working session.
There's a tidy irony here. Days earlier, ReliaQuest's own threat researchers had publicly warned that ShinyHunters was registering domains in the pattern company[.]claims to impersonate help desks. The domain used against ReliaQuest, first reported by BleepingComputer, was reliaquest.claims.
How did the attackers get in?
They used vishing, which is phishing conducted over a phone call rather than email. Once the employee approved the multi-factor push, the attacker had a live session into ReliaQuest's Okta identity dashboard. It's the same help-desk impersonation playbook ShinyHunters has now run against hospitals and financial firms. We reported on the healthcare wave on 29 July, when Health-ISAC warned that single sign-on credentials were walking out the door after similar calls. This isn't a novel AI attack; it's a confidence trick with a login page bolted on.
What did the attacker actually get?
View-only access to an identity dashboard, and nothing else. The attacker could browse the layout of accounts and apps but couldn't open them, because device-trust rules, which verify that the machine attempting a login is a known company device, blocked every follow-up attempt.
"The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched," the company said. ShinyHunters told BleepingComputer the same: no business applications were reached, no persistence was established.
Should customers be worried?
On the facts released so far, no. ReliaQuest's audit stretching back to 21 August found nothing suspicious, and the investigation turned up no sign the attacker moved beyond that single account.
Staff at any organisation using single sign-on should treat a surprise IT call with suspicion, particularly one that ends with "just approve the push on your phone." Real security teams don't typically phone you and ask for that.
| Detail | What happened |
|---|---|
| Attack type | Voice phishing plus fake SSO page |
| Lookalike domain | reliaquest.claims |
| Access gained | View-only, Okta identity dashboard |
| Blocked by | Device-trust controls |
| Audit window | From 21 August, no suspicious activity |
What matters most here is the device-trust layer. One employee made the wrong call; that layer made sure it didn't become a breach. Watch whether ShinyHunters pivots tactics now that device-trust controls have publicly stopped them cold.



