ReliaQuest says a ShinyHunters vish ended in a view-only Okta dashboard
An attacker vished employees and stood up a fake SSO site on reliaquest.claims. One employee entered credentials and approved MFA. Device-trust still blocked apps.

On August 24 BleepingComputer reported that ReliaQuest confirmed a failed data-theft attempt after ShinyHunters claimed a breach. The attacker vished employees and hosted a fake SSO page on reliaquest.claims. One employee entered credentials and approved MFA.
What we know
- The attacker vished employees and used a fake SSO site on reliaquest.claims.
- One employee entered credentials and approved MFA.
- The access was a temporary view-only Okta identity dashboard; device-trust blocked apps.
- ReliaQuest said there was no customer data taken and no persistence.
- ShinyHunters posted Okta screenshots and told BleepingComputer the access was view-only.
Takeaways
- MFA approval was not enough to reach apps once device-trust was in the way.
- ReliaQuest and the group both describe the seat as view-only.
- The phishing domain sat on reliaquest.claims, not on the company’s real SSO host.
Source: BleepingComputer


