Cybersecurity company ReliaQuest has confirmed an attempted breach by the ShinyHunters hacking group. Despite this, the firm asserts that the intrusion’s effects were minimal.
Details of the ShinyHunters Attack
On August 17, ReliaQuest disclosed via a post on X that it had been monitoring a phishing effort by ShinyHunters. This campaign involved domains that followed the ‘company.claims’ URL format.
The hackers have been broadening their social engineering methods, now impersonating legal teams in addition to IT and help desks, ReliaQuest warned.
Evidence of the Cybersecurity Breach
Following the removal of ReliaQuest’s post, screenshots emerged that purportedly showed access to the firm’s Okta dashboard. These images were also shared on ShinyHunters’ platform, accompanied by a message mocking ReliaQuest.
ReliaQuest confirmed on Monday that it had been targeted via social engineering. The attackers had set up a fake domain to host a phishing page mimicking ReliaQuest’s Single Sign-On (SSO) system.
Security Measures and Impact
The attackers contacted several ReliaQuest employees, pretending to be security personnel to lure them to the fraudulent page. Unfortunately, one employee entered their password and validated a push notification, enabling the hackers to momentarily access the identity dashboard.
However, ReliaQuest assured that the hackers only gained view-only access and did not breach any applications, systems, or customer data. The company’s robust security controls prevented further access.
ReliaQuest emphasized that there was no unauthorized access to additional identities, business applications, or customer data beyond login credentials. They refuted claims of a ransomware attack or further compromise.
This incident underscores the importance of maintaining vigilant security practices and the effectiveness of strong security controls in mitigating potential threats.
