Security5 publishers2 min readPublished Updated
ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered
A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.
The Watch · Security desk
What happened
- On August 17 ReliaQuest publicly flagged a ShinyHunters campaign registering domains that place a target company's name under the .claims top-level domain.
- On August 22 a caller impersonating a named ReliaQuest security employee got one teammate to enter a password on a fake SSO page and approve the MFA push.
- ReliaQuest says the resulting access was view only, with no applications or systems reached and no customer data touched.
- SOCRadar reports that a listing naming ReliaQuest went up on a ShinyHunters-linked leak site on August 23, carrying Okta screenshots.
- ReliaQuest calls claims that it was compromised or hit by ransomware false.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Awareness training has no headroom left as the control of record: the vendor's own position is that well-trained people lose to a caller who knows a colleague's name, so the only remaining...
- decision The push factor was satisfied and still bought the defender nothing, which moves the design and procurement question to whether an unmanaged device can open anything at all after a valid sign-in.
- exposure A phished analyst identity at a managed detection provider sits adjacent to other companies' environments, which gives the vendor's own identity provider leverage well beyond its own network.
- contradiction Attacker and victim describe the same limits on the access in the same words, so the leak-site entry reads as reputational pressure rather than evidence, and SOCRadar treats it that way.
BleepingComputer put the lookalike host at reliaquest.claims [7]. That is the pattern ReliaQuest itself had published five days earlier, the target's name or abbreviation under the .claims TLD [2][5], which means the indicator already existed inside the company that then walked into it. The gap was not intelligence. It was that a phone call using a real colleague's name is sufficient [4].
The push notification was approved, so the second factor did exactly what it was built to do and bought nothing [4]. What mattered afterwards was device binding: ReliaQuest says a non-ReliaQuest device cannot reach any application or system, valid credential or not [10]. Its write-up is unusually plain about starting from the assumption that someone will eventually be phished [11]. Containment then followed the identity rather than the endpoint, with sessions terminated, the password expired and every authentication factor reset [12], plus an audit reaching back to August 21 that turned up nothing further [13].
View-only is not harmless. The attacker kept trying to open applications from the dashboard [9], which tells you the session was functioning as a list of what was worth attempting [24]. Nobody has said how many staff were called [4]. The number that actually describes the outcome is how many business applications a valid credential opened from an untrusted device, and on ReliaQuest's account that was zero [23].
Then the strange part. The group listed the company on August 23 with screenshots that appear to show an Okta SSO account [15][16] and a message telling ReliaQuest to leave reporting on it to Mandiant [17]. Speaking to BleepingComputer, ShinyHunters described its own access in the same terms as its victim did [20], in wording identical to the sentence ReliaQuest published [22]. SOCRadar's assessment is that the public taunting does not substantiate the breach claim or demonstrate access to ReliaQuest networks [19]. When the extortion post and the incident report agree on the blast radius, the thing on sale is embarrassment, which is why the firm's denial is aimed at the words compromise and ransomware [18].
The asymmetry is worth naming. The same call, the same entered password and the same approved push, at an organization where the identity provider is effectively the front door, ends in notification letters rather than a blog post. ReliaQuest could publish because the answer to what the session reached was small enough to publish [8].
What to watch
- Whether ShinyHunters posts anything drawn from the session itself rather than screenshots of the Okta dashboard.