BleepingComputer put the lookalike host at reliaquest.claims [7]. That is the pattern ReliaQuest itself had published five days earlier, the target's name or abbreviation under the .claims TLD [2][5], which means the indicator already existed inside the company that then walked into it. The gap was not intelligence. It was that a phone call using a real colleague's name is sufficient [4].
The push notification was approved, so the second factor did exactly what it was built to do and bought nothing [4]. What mattered afterwards was device binding: ReliaQuest says a non-ReliaQuest device cannot reach any application or system, valid credential or not [10]. Its write-up is unusually plain about starting from the assumption that someone will eventually be phished [11]. Containment then followed the identity rather than the endpoint, with sessions terminated, the password expired and every authentication factor reset [12], plus an audit reaching back to August 21 that turned up nothing further [13].
View-only is not harmless. The attacker kept trying to open applications from the dashboard [9], which tells you the session was functioning as a list of what was worth attempting [24]. Nobody has said how many staff were called [4]. The number that actually describes the outcome is how many business applications a valid credential opened from an untrusted device, and on ReliaQuest's account that was zero [23].
Then the strange part. The group listed the company on August 23 with screenshots that appear to show an Okta SSO account [15][16] and a message telling ReliaQuest to leave reporting on it to Mandiant [17]. Speaking to BleepingComputer, ShinyHunters described its own access in the same terms as its victim did [20], in wording identical to the sentence ReliaQuest published [22]. SOCRadar's assessment is that the public taunting does not substantiate the breach claim or demonstrate access to ReliaQuest networks [19]. When the extortion post and the incident report agree on the blast radius, the thing on sale is embarrassment, which is why the firm's denial is aimed at the words compromise and ransomware [18].
The asymmetry is worth naming. The same call, the same entered password and the same approved push, at an organization where the identity provider is effectively the front door, ends in notification letters rather than a blog post. ReliaQuest could publish because the answer to what the session reached was small enough to publish [8].