Cybersecurity agency ReliaQuest has confirmed being focused by hackers affiliated with the infamous ShinyHunters group, however claims the affect of the assault was restricted.
ReliaQuest revealed on August 17 in a put up on X that it had been monitoring a widespread ShinyHunters phishing marketing campaign involving domains with the ‘firm.claims’ URL sample.
The corporate additionally warned that the hacker gang has been increasing its social engineering ways to incorporate authorized crew impersonation alongside IT and assist desk impersonation.
In response to that now-deleted put up, somebody shared a number of screenshots that appeared to point out entry to a ReliaQuest Okta dashboard.
The identical screenshots have been posted on ShinyHunters’ web site, together with a message taunting the safety agency.
ReliaQuest addressed the incident on Monday, admitting it had been focused in a social engineering assault over the weekend.
In keeping with the corporate, the hackers registered a faux area and set it as much as host a ReliaQuest SSO phishing web page.
“The risk actor then known as a number of ReliaQuest teammates, every time posing as a safety worker by identify in an try and steer them in direction of the faux web page,” the safety agency defined. “One teammate entered their password and permitted the push notification on their telephone. That handed the attacker a short session on our identification dashboard.”
ReliaQuest says the attackers obtained view-only entry to the dashboard, and identified that its functions, programs, and buyer knowledge weren’t compromised.
“The risk actor continued with makes an attempt to entry these functions from the dashboard however was constantly denied as a result of safety controls in place,” it famous.
ReliaQuest added, “No further identities have been accessed, no enterprise functions have been reached, no buyer or ReliaQuest knowledge was accessed past the person’s login credentials, and no persistence was established. Claims that ReliaQuest was compromised or focused by ransomware are false.”
Associated: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Marketing campaign
Associated: Private Info Uncovered in Apollo International Knowledge Breach
Associated: 1.6 Million Seemingly Impacted by RingCentral Knowledge Breach







