ReliaQuest confirms ShinyHunters access was limited
ReliaQuest confirmed attackers tied to ShinyHunters used a fake SSO page and phone-based social engineering to gain brief view-only access to its Okta dashboard; no systems, apps or customer data were accessed.
ReliaQuest confirmed hackers affiliated with the ShinyHunters group registered a fake domain, built a single sign-on phishing page and called employees while posing as security staff. An employee who entered credentials and approved an authentication push gave the attackers a short, view-only session on the company’s Okta identity dashboard.
ReliaQuest first reported the phishing campaign on August 17 and said the attackers used domains following the ‘company.claims’ pattern. The company noted the group expanded impersonation tactics to include legal teams in addition to IT and help desk staff. Screenshots that appeared to show an Okta dashboard were shared after an initial post was deleted and later posted on the attackers’ website alongside a taunting message.
Attempts from the dashboard to reach business applications were blocked by the firm’s existing security controls. ReliaQuest reported no systems, business applications or customer data were accessed beyond the single user’s login credentials. The company added that no additional identities were accessed and no persistence was established.
ReliaQuest described the incident as occurring over a weekend and disclosed it publicly the following Monday. The firm said it tracked the campaign, shared details with employees and partners to help identify the fraudulent domains and the phone-based social engineering techniques, and maintained that claims of a broader compromise or ransomware were false.
ReliaQuest wrote, “One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”








