ReliaQuest Faces ShinyHunters Social Engineering Attack, but Says Security Controls Stopped a Wider Breach + Video

Listen to this Post

Featured Image

Introduction: When the Defenders Become the Target

Cybersecurity companies spend their days helping other organizations prepare for attacks, detect intrusions, and stop threat actors before the damage spreads. But no organization, including a company built around security operations, is completely immune to human-targeted attacks.

ReliaQuest recently found itself on the receiving end of a sophisticated social engineering campaign linked to the notorious ShinyHunters group. The incident is particularly interesting because the attackers did not reportedly break through a firewall, deploy a destructive exploit, or compromise customer systems. Instead, they targeted the one component that continues to challenge even mature security environments: human trust.

According to ReliaQuest, one employee was persuaded to enter credentials into a fake single sign-on page and approve a push notification. The attackers briefly gained access to an identity dashboard, but the company says additional security controls prevented them from reaching business applications, customer data, or other identities.

The incident offers an uncomfortable but valuable lesson for the cybersecurity industry. Modern defenses can be incredibly effective, yet attackers increasingly understand that they do not always need to defeat sophisticated technology. Sometimes, all they need is a convincing phone call, a believable identity, and a victim who is pressured into approving the wrong authentication request.

The Original Incident: ReliaQuest Confirms a Targeted Social Engineering Attack

Cybersecurity firm ReliaQuest confirmed that it was targeted in a social engineering attack associated with hackers affiliated with ShinyHunters.

Before publicly acknowledging the incident, ReliaQuest had reportedly been tracking a broader phishing campaign involving domains using a company.claims pattern. The company also warned that attackers were expanding their impersonation tactics.

Instead of limiting themselves to pretending to be IT personnel or help desk employees, the attackers were also reportedly impersonating individuals connected to legal teams. This represents an important evolution in social engineering because attackers are constantly searching for identities that employees are less likely to challenge.

A fake IT employee may trigger suspicion.

A fake lawyer discussing an urgent legal issue may create a completely different kind of pressure.

That psychological manipulation is becoming a major part of modern cyberattacks.

The Screenshots That Drew Attention to the Incident

The situation gained additional attention after screenshots appeared online that seemed to show access to a ReliaQuest Okta dashboard.

The screenshots were reportedly shared in response to ReliaQuest’s discussion of the broader ShinyHunters phishing campaign. They later appeared on infrastructure associated with ShinyHunters alongside a message intended to mock the cybersecurity company.

For an organization whose business involves protecting companies from cyber threats, the public exposure created an obvious reputational challenge.

However, access to a dashboard does not automatically mean access to everything behind it.

Identity platforms often act as gateways to multiple applications, but modern security architecture can apply additional restrictions based on the user, device, location, authentication state, application, risk score, and other contextual signals.

That distinction became central to

The Attack Started With a Fake Domain

According to ReliaQuest, the attackers registered a fraudulent domain and used it to host a phishing page designed to imitate the company’s single sign-on environment.

The purpose was straightforward.

Convince an employee that the page was legitimate.

Capture their credentials.

Then use those credentials to obtain authenticated access.

But the campaign reportedly went further than a conventional phishing email.

The attackers called multiple ReliaQuest employees and impersonated a real security employee by name. During these conversations, the goal was reportedly to direct employees toward the fraudulent authentication page.

This approach combines technical deception with direct psychological pressure.

The fake website creates visual credibility.

The phone call creates urgency.

The impersonation creates trust.

Together, those elements can be far more dangerous than a traditional phishing message sitting quietly in an inbox.

One Employee Approved the Authentication Request

ReliaQuest said that one employee entered their password into the phishing page and approved a push notification on their phone.

That approval reportedly gave the attacker a brief authenticated session on the company’s identity dashboard.

This is a powerful example of why multi-factor authentication, while essential, is not automatically invulnerable to social engineering.

Many people think MFA creates an absolute barrier.

It does not.

If an attacker successfully manipulates a legitimate user into approving an authentication request, the attacker may effectively convince the security system that they are the legitimate user.

This type of attack is often associated with MFA fatigue, push bombing, or adversary-in-the-middle phishing, depending on the technical structure of the operation.

The security control still exists.

The attacker simply attempts to manipulate the person responsible for approving it.

The Attackers Reached the Identity Dashboard, but ReliaQuest Says the Access Was Limited

ReliaQuest stated that the attackers obtained view-only access to the identity dashboard.

According to the company, the threat actor attempted to continue from that point and access additional applications available through the dashboard.

Those attempts were reportedly blocked.

ReliaQuest said that its security controls consistently denied access to the targeted applications.

The company further stated that the intrusion did not result in access to additional identities, business applications, customer information, or other ReliaQuest data beyond the affected user’s login credentials.

ReliaQuest also said that the attackers did not establish persistence inside its environment.

That is an important distinction.

A temporary authenticated session can still be a serious security event.

But a brief session that is rapidly contained is very different from a persistent compromise involving lateral movement, privileged access, data theft, or ransomware deployment.

Customer Data Was Reportedly Not Accessed

ReliaQuest said that its applications, internal systems, and customer data were not compromised during the incident.

According to the company’s account, the attacker’s access remained limited and did not expand into the broader environment.

The company specifically stated that no additional identities were accessed and that no business applications were successfully reached.

It also rejected claims that the company had suffered a wider compromise or ransomware incident.

Based on

Still, the incident demonstrates how close a phishing event can come to becoming something much more serious.

In many modern environments, identity is the front door.

Once attackers obtain a valid authenticated session, the next question becomes simple.

What else can that identity access?

Why ShinyHunters and Similar Groups Are So Dangerous

Groups associated with major data theft campaigns have increasingly demonstrated that technical sophistication is not always the only factor that matters.

Social engineering can be scalable.

It can be inexpensive.

And when executed effectively, it can bypass assumptions that organizations make about their own security maturity.

Attackers do not necessarily need to discover a zero-day vulnerability if they can convince an employee to voluntarily provide credentials.

They do not always need to exploit an authentication flaw if they can manipulate a user into approving a legitimate MFA request.

They do not always need malware if they can obtain access through trusted identity infrastructure.

This is why identity has become one of the most valuable targets in modern cybercrime.

The Human Layer Remains a Critical Security Boundary

Organizations often invest heavily in endpoint detection, cloud monitoring, network segmentation, encryption, vulnerability management, and threat intelligence.

All of these technologies are important.

But social engineering attacks target a different layer.

They target decision-making.

An employee may understand that phishing exists.

They may know that attackers impersonate IT staff.

They may even receive regular security awareness training.

But during a convincing live phone call, context can change everything.

An attacker may know the name of an employee.

They may know the

They may understand the internal language used by the organization.

They may create a sense of urgency.

They may claim that an account is under attack and that immediate action is required.

At that point, the employee is no longer simply evaluating a suspicious email.

They are making a rapid decision while under pressure.

That is exactly where sophisticated social engineering becomes dangerous.

Legal Team Impersonation Could Become an Important New Tactic

ReliaQuest warned that the phishing campaign was expanding beyond traditional IT and help desk impersonation.

The reported use of legal team identities deserves particular attention.

Employees may be trained to question unexpected calls from IT.

They may be less prepared to challenge someone claiming to represent legal counsel, compliance, or an urgent internal investigation.

Attackers understand organizational psychology.

Different departments carry different levels of authority.

A help desk employee may ask for technical information.

A security employee may request an MFA approval.

A legal representative may create fear around compliance, confidentiality, litigation, or urgent corporate matters.

By diversifying impersonation roles, attackers increase their chances of finding a scenario that works.

Identity Security Is Becoming the New Perimeter

Traditional cybersecurity once focused heavily on the network perimeter.

The organization protected the firewall.

The internal network was considered relatively trusted.

The modern environment is very different.

Employees work remotely.

Applications operate in the cloud.

Partners connect through APIs.

Users access systems from multiple devices.

Identity now sits at the center of the environment.

A compromised identity can potentially open access to email, cloud storage, internal applications, administrative portals, and third-party services.

That is why organizations must assume that an authenticated session alone should not automatically grant unrestricted trust.

ReliaQuest’s description of the incident suggests that additional security controls prevented the compromised session from moving deeper into the environment.

That layered approach may have been the difference between a short-lived identity incident and a significantly larger security crisis.

What Undercode Say:

The Real Story Is Not That ReliaQuest Was Phished

The most important lesson is not simply that a cybersecurity company became a target.

Every organization is a target.

The more interesting question is what happened after the attackers successfully convinced one user to authenticate.

That is where the strength of the security architecture was tested.

A phishing-resistant organization should not depend on the assumption that users will never make mistakes.

It should assume that mistakes will eventually happen.

The real defense begins after the first layer fails.

Identity Platforms Need Multiple Independent Controls

A password should not be enough.

A password plus a push notification should also not automatically mean unrestricted access.

Organizations need contextual controls around authentication.

Risk-based authentication can evaluate unusual behavior.

Device trust can identify unmanaged systems.

Conditional access can restrict sensitive applications.

Session monitoring can identify suspicious activity.

Privileged actions can require stronger verification.

The objective is to prevent one compromised session from becoming a complete compromise.

Push-Based MFA Still Has a Human Weakness

Push notifications are convenient.

Convenience is valuable for users.

But convenience can also create an attack surface.

A user may receive repeated authentication requests.

They may approve one to stop the notifications.

They may believe a caller who claims that approval is required.

They may approve a request while distracted.

Phishing-resistant authentication methods such as hardware-backed authentication and FIDO-based approaches can reduce some of these risks because authentication is more strongly connected to the legitimate service and domain.

Social Engineering Is Becoming More Personalized

The era of generic phishing emails is not disappearing, but attackers are becoming more selective.

Instead of sending millions of identical messages, threat actors can combine public information, corporate data, breached information, social media intelligence, and automated research.

They can identify employees.

They can identify technologies.

They can identify departments.

They can imitate real people.

They can then construct believable scenarios around that information.

Artificial intelligence may further accelerate this process by helping attackers generate convincing messages and scripts at scale.

Security Awareness Training Must Become Scenario-Based

Employees should not only be shown suspicious emails.

They should practice realistic situations.

What happens if someone calls and claims to be from security?

What happens if they know the name of your manager?

What happens if they claim there is an active incident?

What happens if they ask you to approve an authentication request immediately?

Organizations should teach employees that security teams should have clear and predictable procedures for identity verification.

Employees should know how to independently verify an unexpected request.

Attackers Are Testing Organizational Trust

Social engineering is ultimately an attack against trust relationships.

The attacker wants the employee to trust the caller.

The employee trusts the identity provider.

The identity provider trusts the approved MFA request.

Applications trust the authenticated session.

This chain can become dangerous if trust is granted too broadly.

Zero-trust principles attempt to reduce that problem by continuously evaluating context instead of assuming that authentication creates permanent trust.

Session Controls Are Just as Important as Login Controls

Many security discussions stop at authentication.

But attackers care about sessions.

Once authenticated, the question becomes what the session can do.

Organizations should monitor session creation.

They should detect unusual geographic changes.

They should identify impossible travel scenarios.

They should monitor unusual application access.

They should revoke suspicious sessions quickly.

Fast session revocation can dramatically reduce the value of stolen credentials.

Least Privilege Continues to Matter

The affected identity should only have access to what it genuinely needs.

If an ordinary user account can reach every critical application, one phishing event can become catastrophic.

If access is segmented, the attacker has fewer opportunities.

Least privilege does not eliminate phishing.

It reduces the blast radius.

That difference is critical.

The Incident Also Demonstrates the Importance of Detection

ReliaQuest was able to investigate and publicly describe the attack.

This indicates the importance of monitoring identity activity.

Organizations should know when a user logs in.

They should know from where.

They should know what applications are accessed.

They should know whether the behavior is normal.

Detection cannot prevent the first mistake.

It can prevent the second, third, and fourth stages of an intrusion.

Public Exposure Adds Another Layer of Pressure

When attackers publish screenshots or claim access publicly, the incident becomes more than a technical event.

It becomes a communications crisis.

The organization must investigate quickly.

It must determine what actually happened.

It must distinguish evidence from exaggeration.

And it must communicate accurately without minimizing a genuine security event.

That balance is difficult.

Security Companies Are High-Value Targets

A cybersecurity company may hold valuable knowledge about security tools, detection methods, customers, and enterprise environments.

That makes such organizations attractive targets.

But this also means their internal environments should be treated as highly contested territory.

Threat actors may attempt repeated attacks.

They may study public statements.

They may impersonate employees.

They may exploit the

The defender is never automatically protected because it is a security company.

The Best Defense Is Layered Failure

No single employee should be capable of accidentally exposing the entire organization.

No single password should unlock everything.

No single MFA approval should bypass every control.

No single session should create unlimited access.

Security architecture should be designed around controlled failure.

One layer can fail.

The next layer should stop the attacker.

The ReliaQuest Incident Is a Warning for Every Organization

The incident should not be viewed as a story relevant only to cybersecurity companies.

Any organization using SSO, cloud applications, identity dashboards, and push-based MFA can face similar social engineering attempts.

The attackers do not need to be technically superior.

They only need one successful interaction.

That is why preparation must focus on both technology and people.

The Final Analytical Conclusion

The most significant lesson from this incident is simple.

Authentication is not the same as trust.

A successful login should not end security verification.

It should begin a new stage of risk evaluation.

Organizations that continuously validate identities, devices, sessions, and behavior will be significantly better positioned when a phishing attack eventually succeeds.

Because eventually, somewhere, someone will click.

The real question is whether the attacker can go any further.

Deep Analysis: Testing and Hardening the Identity Attack Surface

Linux Command: Inspect Suspicious Authentication Activity

Security teams can review authentication-related activity from local logs using commands such as:

sudo journalctl -u ssh --since "24 hours ago"

This can help administrators identify unusual login attempts and authentication activity on Linux systems.

Linux Command: Review Recent Successful Logins

Administrators can inspect recent user sessions with:

last -a | head -50

Unexpected locations, unusual accounts, or abnormal login times should be investigated.

Linux Command: Check Failed Authentication Attempts

On systems where authentication events are written to standard logs, teams can review failed attempts with:

sudo grep "Failed password" /var/log/auth.log | tail -50

Repeated failures can indicate password guessing, automated attacks, or an attacker attempting to use compromised credentials.

Linux Command: Review Active Sessions

Security teams can identify currently logged-in users with:

who

Additional session details can be examined with:

w

These commands provide a quick view of active local sessions.

Linux Command: Identify Active Network Connections

Investigators can inspect active connections using:

sudo ss -tulpn

For broader connection analysis:

sudo ss -tpn

Unexpected outbound connections should be correlated with endpoint, identity, and application logs.

Linux Command: Search Security Logs for Suspicious Events

A basic investigation can include searching for authentication-related activity:

sudo journalctl --since "2 hours ago" | grep -Ei "authentication|login|session|failed"

This approach should be combined with centralized identity logs rather than relying only on individual endpoints.

Defensive Analysis: Reduce the Value of Stolen Sessions

Organizations should consider stronger authentication methods for sensitive applications.

They should enforce least privilege.

They should use conditional access.

They should monitor session behavior.

They should rapidly revoke suspicious sessions.

They should require additional verification for privileged operations.

The goal is not to assume that phishing will never succeed.

The goal is to ensure that a successful phishing event has as little operational value to the attacker as possible.

Confirmed Incident: ReliaQuest Acknowledged a Social Engineering Attack

✅ ReliaQuest publicly acknowledged that it was targeted through a social engineering operation involving a fake domain and an impersonation campaign.

Confirmed Limited Access: An Authenticated Session Was Obtained

✅ The company’s account states that one employee entered credentials into the phishing page and approved a push notification, resulting in brief access to an identity dashboard.

No Evidence in the Provided Information of a Wider Compromise

✅ According to ReliaQuest’s public statement, the attackers did not access additional identities, business applications, customer data, or establish persistence, and the company rejected claims of a ransomware-related compromise.

Prediction

(-1) The negative prediction is that social engineering campaigns will continue becoming more convincing and more personalized, especially against organizations that rely heavily on cloud identity platforms and push-based MFA.

Attackers are likely to expand impersonation beyond IT teams into legal, finance, HR, executive, and compliance roles.

More organizations may face attacks where legitimate credentials and approved MFA requests are used as the initial entry point.

Companies that treat successful authentication as permanent trust may face greater risk of lateral movement after phishing incidents.

The strongest defensive trend will likely involve phishing-resistant authentication, continuous session monitoring, contextual access controls, and rapid identity-based incident response.

The long-term battle will increasingly focus on identity, because in the cloud era, the person who controls the login session may be only one step away from controlling the business.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.securityweek.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube