On 22 August an attacker phoned several employees at ReliaQuest, an American managed detection and response provider, and presented themselves as a named member of the company’s own security team. One employee entered their credentials on a cloned single sign-on page and approved the MFA push that followed. That was enough to open a live session on ReliaQuest’s Okta identity dashboard.
The session was view-only. Device-trust policy blocked every attempt to launch an application from the dashboard and ReliaQuest says it then terminated the sessions, revoked the exposed password and reset all authentication tokens. Its statement leaves little room, “No ReliaQuest applications or systems were accessed, and no customer data was ever touched.”
ShinyHunters listed the company on its data leak site the next day 23rd August with screenshots of the Okta dashboard attached.
The Domain Was reliaquest.claims
Six days before the phone rang, on 17 August, ReliaQuest’s own threat research team had published a warning about the campaign that would go on to hit it. The group was registering domains under the .claims top-level domain placing the target organisation’s name or its abbreviation in front of the suffix and using them to impersonate help desks, IT departments and more recently, legal teams. The domain used against ReliaQuest was reliaquest.claims, according to sources.
The credential-harvesting page sat behind a content delivery network which puts a reputable IP address in front of a hostile site and buys the operator hours before a takedown lands. None of the tradecraft is new. ReliaQuest’s own account of the playbook lists disposable lookalike domains, cloned login pages behind a CDN, MFA push abuse and an immediate attempt to enrol a new authentication method under the attacker’s control.
MFA Approved the Login. Device Trust Refused It.
That distinction matters more than the outcome. A push notification confirms that whoever holds the enrolled phone tapped approve. It says nothing about which device is asking, where the request came from or whether the login page was genuine. Once the employee approved, Okta had a session it treated as legitimate.
The control that stopped the escalation was a separate one. Device trust requires the connecting machine to be enrolled and managed before an application will open and it does not care how convincing the phone call was. ReliaQuest reports that the attacker kept trying applications from the dashboard and was refused each time. The firm has since audited device trust and on-network access back to 21 August and found nothing further.
Both Sides Tell the Same Story. That Is Not Verification.
ReliaQuest says the attacker never got past the dashboard. ShinyHunters said the same thing, no other identities reached, no business applications opened, nothing taken beyond the one set of login credentials, no persistence established. Agreement between a victim and the group extorting it is rare enough to notice.
It is not corroboration. ReliaQuest is a security vendor reporting on itself and the version of events where its own controls hold is the version worth money to it. ShinyHunters has a different motive pointing in the same direction, publicly embarrassing an MDR provider is worth more to the group than a data haul it cannot demonstrate. The screenshots on the leak site show a dashboard, not exfiltration. No independent party has verified either account.
The group’s reply to ReliaQuest’s research post on X ran to three words, “Who’s hunting who ?”, followed by the screenshots. Both the post and the reply were deleted from X and the images resurfaced on the leak site on 23 August, according to SOCRadar. ReliaQuest has rejected claims of a wider compromise and descriptions of the incident as ransomware as false.
Pandora Met the Same Group Through a Third Party
Nordic exposure to ShinyHunters is not hypothetical. Danish jeweller Pandora wrote to customers in August 2025 to say that some of their information had been accessed through a third-party platform the company uses, limited to names and email addresses, with no passwords or payment details taken. Pandora did not name the group. BleepingComputer connected the incident to the ShinyHunters campaign against corporate Salesforce instances that ran through that summer alongside Chanel, Adidas, Qantas and Allianz Life.
Google Threat Intelligence which tracks the group as UNC6040, documented the method in June 2025, a phone call posing as internal IT, then credentials and MFA tokens handed over by the employee. A year later the same play is being run against a company whose product is detecting it. If your brand is recognisable and your help desk sits with a supplier, you are already on the list.
Search for Your Own Name Under .claims This Week
Lookalike domain registration is public. Certificate transparency logs will show a new .claims domain carrying your company name or its abbreviation usually within hours of the certificate being issued. Add the newer generic top-level domains to whatever typosquat monitoring you already run. A month ago .claims was on almost nobody’s list.
Four controls decide whether a successful phish becomes an incident:
- Phishing-resistant MFA, FIDO2 or passkeys, on identity dashboards and every administrative account. A push notification cannot tell a cloned SSO page from the real one.
- Device trust or equivalent managed-device conditional access enforced across all applications rather than the important ones. This is the control that held at ReliaQuest.
- Alerting on the enrolment of a new authentication method. Attackers attempt it within minutes of taking a session.
- Help desk callback verification on a number taken from the internal directory applied even when the caller names a real colleague because in this campaign the caller did.
ReliaQuest published a technical account of the attack the day after it happened which is faster than most companies manage and worth copying. The employee who approved that push did what push notifications train people to do. The control that stopped the attack was configured long before the phone rang.
References
- ReliaQuest Confirms Failed Data-theft Attack After ShinyHunters Breach
- Threat Spotlight: Social Engineering Attempt Against ReliaQuest
- ShinyHunters and ReliaQuest Trade Blows Over Claimed Breach
- ReliaQuest Says Claimed ShinyHunters Attack Was Successfully Blocked
- ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
This post is also available in:

