ReliaQuest: How ReliaQuest Stopped a ShinyHunters Breach Attempt

ReliaQuest: How ReliaQuest Stopped a ShinyHunters Breach Attempt

ReliaQuest Thwarts ShinyHunters Social Engineering Attack Targeting Okta SSO

On 23 August 2026, cybersecurity firm ReliaQuest confirmed a social engineering attack linked to the ShinyHunters threat group, which attempted to breach its systems using a fake Okta Single Sign-On (SSO) page. The attackers, posing as IT support, tricked an employee into approving a multi-factor authentication (MFA) push during an impersonation call, granting them access to a view-only identity dashboard session.

The breach was contained quickly due to ReliaQuest’s layered security controls, including device-trust policies that restricted the attacker to a single session. No business applications, customer data, or company data were accessed, and no persistence was established. The compromised credentials were immediately expired and reset upon detection.

The attack followed a well-documented playbook: threat actors registered a lookalike domain, hosted a fake SSO page behind a content delivery network (CDN), and used phone-based impersonation to deceive the employee. The incident mirrored a recently disclosed WordPress plugin flaw that allowed authentication bypass, reinforcing the need for defense-in-depth strategies rather than reliance on single security measures.

ReliaQuest’s GreyMatter platform, which integrates with Splunk, CrowdStrike, Fortinet, and Google Cloud Chronicle, played a key role in normalizing telemetry data and enabling rapid response. The company emphasized that phishing remains effective, particularly when attackers leverage employee names and urgency to manipulate victims.

A week prior, ReliaQuest’s threat research team had shared intelligence on ShinyHunters, highlighting the group’s use of fake domains and MFA bypass techniques. The screenshots of the compromised Okta dashboard, initially posted on X (formerly Twitter), were later deleted. The incident underscores the growing sophistication of social engineering attacks, even against cybersecurity providers.

Source: https://cybermagazine.com/news/how-reliaquest-stopped-a-shinyhunters-breach

ReliaQuest cybersecurity rating report: https://www.rankiteo.com/company/reliaquest

"id": "REL1787660926",
"linkid": "reliaquest",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'customers_affected': 'None',
                        'industry': 'Cybersecurity',
                        'name': 'ReliaQuest',
                        'type': 'Cybersecurity Firm'}],
 'attack_vector': 'Fake Okta SSO page, MFA push manipulation, phone-based '
                  'impersonation',
 'data_breach': {'data_exfiltration': 'No',
                 'personally_identifiable_information': 'No',
                 'type_of_data_compromised': 'None'},
 'date_detected': '2026-08-23',
 'date_publicly_disclosed': '2026-08-23',
 'date_resolved': '2026-08-23',
 'description': 'On 23 August 2026, cybersecurity firm ReliaQuest confirmed a '
                'social engineering attack linked to the ShinyHunters threat '
                'group, which attempted to breach its systems using a fake '
                'Okta Single Sign-On (SSO) page. The attackers, posing as IT '
                'support, tricked an employee into approving a multi-factor '
                'authentication (MFA) push during an impersonation call, '
                'granting them access to a view-only identity dashboard '
                'session. The breach was contained quickly due to ReliaQuest’s '
                'layered security controls, including device-trust policies '
                'that restricted the attacker to a single session. No business '
                'applications, customer data, or company data were accessed, '
                'and no persistence was established. The compromised '
                'credentials were immediately expired and reset upon '
                'detection.',
 'impact': {'data_compromised': 'None',
            'operational_impact': 'Minimal (contained quickly)',
            'systems_affected': 'Okta identity dashboard (view-only session)'},
 'initial_access_broker': {'backdoors_established': 'No',
                           'entry_point': 'Fake Okta SSO page, lookalike '
                                          'domain'},
 'investigation_status': 'Contained and resolved',
 'lessons_learned': 'The incident underscores the growing sophistication of '
                    'social engineering attacks, even against cybersecurity '
                    'providers. Defense-in-depth strategies are critical, and '
                    'phishing remains effective when attackers leverage '
                    'employee names and urgency.',
 'post_incident_analysis': {'corrective_actions': 'Credential reset, '
                                                  'device-trust policies '
                                                  'enforcement, enhanced '
                                                  'monitoring',
                            'root_causes': 'Social engineering (MFA push '
                                           'manipulation), fake Okta SSO page, '
                                           'phone-based impersonation'},
 'recommendations': 'Implement layered security controls, enforce device-trust '
                    'policies, and educate employees on social engineering '
                    'tactics.',
 'references': [{'source': 'ReliaQuest Threat Research Team'},
                {'source': 'X (formerly Twitter)'}],
 'response': {'containment_measures': 'Device-trust policies, credential '
                                      'expiration and reset',
              'enhanced_monitoring': 'GreyMatter platform integration with '
                                     'Splunk, CrowdStrike, Fortinet, and '
                                     'Google Cloud Chronicle',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Compromised credentials expired and '
                                      'reset'},
 'threat_actor': 'ShinyHunters',
 'title': 'ReliaQuest Thwarts ShinyHunters Social Engineering Attack Targeting '
          'Okta SSO',
 'type': 'Social Engineering',
 'vulnerability_exploited': 'Human vulnerability (social engineering), '
                            'potential WordPress plugin flaw (authentication '
                            'bypass)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.