Circuit Wire — a daily news update from the Circuit.
Cybersecurity firm ReliaQuest confirmed over the weekend that attackers telephoned several of its employees while posing as a member of its own security team and tried to steer them to a fake single sign-on page.
The page sat on a lookalike domain, reliaquest.claims, hosted behind a content delivery network. The callers used the name of a real ReliaQuest security employee. One targeted employee entered credentials on the fake page and approved a multi-factor authentication push. That handed the attacker temporary access to the company's identity dashboard.
Device-trust controls then blocked every attempt to open applications from that dashboard. "The extent of the access was view-only," ReliaQuest said in its own account of the incident. The company said no applications or systems were accessed and no customer data was touched. It terminated the attacker's sessions, revoked the exposed password and reset all authentication tokens.
The investigation found no persistence on ReliaQuest systems and no access to other accounts, apps or data. The firm said it audited its control fidelity, device trust and on-network access from August 21 onward and identified no suspicious activity.
The extortion group ShinyHunters claimed the intrusion on its leak site, publishing screenshots of a compromised Okta single sign-on account and referring back to ReliaQuest's earlier reporting on the group. A newly created account on X, believed to be linked to the attackers, had already replied to ReliaQuest with a taunt and the same screenshots. Both posts were later taken down. ShinyHunters told BleepingComputer its access was view-only, that no business applications were reached and that no persistence was established.
ReliaQuest's threat research team had warned last week that ShinyHunters was registering domains under the .claims top-level domain to impersonate corporate help desks and IT teams. The domains carry the target organization's name or abbreviation ahead of that suffix. The company said the campaign is widespread.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

