ShinyHunters phoned a ReliaQuest employee, and one of them fell for it
The security firm says a vishing call led to a view-only peek at its Okta dashboard, but device-trust rules stopped anything worse.

Key points
- ReliaQuest confirmed on the weekend that an employee was tricked by a phone-based phishing call and entered credentials into a fake single sign-on page at reliaquest.claims.
- The attacker, linked to the extortion group ShinyHunters, gained view-only access to ReliaQuest's Okta identity dashboard after the employee approved a multi-factor prompt.
- Device-trust controls blocked every attempt to open actual applications from that dashboard, and ReliaQuest says no customer data was touched.
- ShinyHunters published screenshots on its leak site and taunted ReliaQuest on X after the security firm had earlier flagged the group's use of company[.]claims lookalike domains.
- ReliaQuest revoked the exposed password, killed the attacker's sessions, and reset authentication tokens; an audit going back to 21 August found no other suspicious activity.
Cybersecurity firm ReliaQuest has admitted that one of its own staff was fooled by a phone scam, in an incident the extortion crew ShinyHunters is loudly claiming as a win.
The attackers called ReliaQuest employees pretending to be someone from the internal security team. They pointed victims at a fake login page dressed up to look like ReliaQuest's single sign-on, which is the one company password screen staff use to reach all their work tools.
One employee bit. They typed their password into the fake page and then tapped approve on the multi-factor prompt that landed on their phone, handing the caller a working session.
There is a tidy irony here. Days earlier, ReliaQuest's own threat researchers had publicly warned that ShinyHunters was registering domains in the pattern company[.]claims to impersonate help desks. The domain used against ReliaQuest, first reported by BleepingComputer, was reliaquest.claims.
How did the attackers get in?
They used vishing, which is phishing done over a phone call instead of email. The caller name-dropped a real ReliaQuest security employee to sound credible, then walked the target to a fake sign-on page hosted behind a content delivery network to make the address look less suspicious.
Once the employee approved the multi-factor push notification, the attacker had a live session into ReliaQuest's Okta identity dashboard. This is the classic MFA-fatigue playbook that groups like ShinyHunters and Scattered Spider have run against dozens of companies over the past two years. If it feels familiar, that is because it is: a help-desk impersonation call is basically social engineering's version of an old-school confidence trick, with a login page bolted on.
What did the attacker actually get?
View-only access to an identity dashboard, and nothing else, according to ReliaQuest. The attacker could see the layout of accounts and apps but could not open them, because device-trust rules, which check that the computer trying to log in is a known company machine, blocked every follow-up attempt.
"The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched," the company said. ShinyHunters, oddly, confirms the same limits, telling reporters no business applications were reached and no persistence was set up.
Should customers be worried?
On the facts released so far, no. ReliaQuest says its investigation found no sign the attacker moved beyond that single account, and an audit stretching back to 21 August turned up nothing suspicious.
Staff at any company that uses single sign-on should treat a surprise phone call from IT with suspicion, especially one that ends with "just approve the push on your phone". Real security teams do not usually ring you and ask for that.
| Detail | What happened |
|---|---|
| Attack type | Voice phishing plus fake SSO page |
| Lookalike domain | reliaquest.claims |
| Access gained | View-only, Okta identity dashboard |
| Blocked by | Device-trust controls |
| Audit window | From 21 August, no suspicious activity |
The episode is a useful reminder that layered controls do work. One employee made the wrong call. The device-trust layer behind them made sure that mistake did not turn into a breach.



