Cybersecurity firm ReliaQuest recently confirmed a sophisticated social engineering attempt by the notorious data extortion group ShinyHunters, which targeted one of its employees. While an initial breach of an Okta Single Sign-On (SSO) account occurred, ReliaQuest’s internal security controls successfully prevented any access to core applications or customer data, marking the incident as a failed data-theft attack, according to BleepingComputer.
This incident highlights the persistent threat of social engineering, even against security-conscious organizations, and underscores the critical importance of layered defenses that extend beyond initial authentication.
Attack Details and ShinyHunters Social Engineering Tactics
The attack unfolded as a multi-stage social engineering campaign, primarily leveraging vishing (voice phishing) and carefully crafted phishing pages. The threat actors, believed to be linked to ShinyHunters, initiated contact by calling multiple ReliaQuest employees, impersonating a member of the company’s security team. Their objective was to manipulate employees into accessing a deceptive ReliaQuest single sign-on page, hosted behind a content delivery network on a lookalike domain, which sources identified as reliquest.claims.
The Vishing and Phishing Campaign
The choice of the .claims Top-Level Domain (TLD) is part of a broader ShinyHunters social engineering tactics, as ReliaQuest’s own Threat Research team had previously tracked this group registering similar domains (e.g., company.claims) to impersonate help desks and IT teams for various organizations. This strategic use of .claims domains aimed to create a convincing façade for their phishing infrastructure.
During one such vishing attempt, a targeted employee fell victim to the ruse. They entered their credentials on the fake SSO page and subsequently approved a multi-factor authentication (MFA) push notification. This action granted the attacker temporary, view-only access to ReliaQuest’s identity dashboard through the compromised Okta SSO account.
ReliaQuest Incident Response Details
Crucially, ReliaQuest’s device-trust controls immediately identified the unauthorized access attempts. These controls successfully blocked all subsequent efforts by the threat actor to access internal applications through the dashboard. ReliaQuest affirmed that “The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched.” The company swiftly responded by terminating the attacker’s sessions, revoking the exposed password, and resetting all authentication tokens associated with the compromised account. Their subsequent investigation found no evidence of access to other accounts, applications, or data, nor any signs of persistence established on ReliaQuest’s systems.
The incident gained public attention when an X account, thought to be associated with ShinyHunters, replied to ReliaQuest’s previous post about the .claims campaign, sharing screenshots of the compromised Okta SSO account. These same screenshots later appeared on ShinyHunters’ data leak site, effectively claiming responsibility for the breach attempt. However, ReliaQuest’s statement confirms the failure of the data theft aspect.
Analysis and Mitigation: Okta SSO Protection Strategies
This incident provides a valuable case study in the ongoing battle against sophisticated social engineering. While the initial compromise of credentials and MFA approval demonstrates the effectiveness of ShinyHunters’ vishing techniques, ReliaQuest’s defense-in-depth approach, particularly the implementation of device-trust controls, proved instrumental in preventing a significant data breach. This underscores that Okta SSO protection strategies must extend beyond basic authentication to include contextual access policies.
Organizations must recognize that even with MFA enabled, social engineering can bypass these protections if employees are tricked into approving legitimate-looking but malicious prompts. This is where advanced detection and enforcement mechanisms, such as device trust and behavioral analytics, become critical.
Recommendations for Defenders
To safeguard against similar sophisticated attacks and enhance ReliaQuest incident response details learnings, security professionals should prioritize the following:
- Enhance Employee Training: Conduct regular, comprehensive training programs focused on identifying advanced social engineering tactics, including vishing calls and lookalike phishing domains. Employees must be aware of the tricks used to bypass MFA, such as prompt bombing or convincing users to approve unauthorized pushes.
- Implement Device-Trust Controls: Beyond basic authentication, integrate device-trust policies that verify the health, compliance, and registration status of devices attempting to access corporate resources. This prevents access from unknown or untrusted devices, even with valid credentials.
- Strengthen MFA: While MFA is essential, consider moving beyond simple push notifications to more secure methods like FIDO2/WebAuthn hardware tokens, which are phishing-resistant. Also, implement risk-based MFA that requires stronger authentication factors in unusual access scenarios.
- Monitor Identity and Access Logs: Continuously monitor Okta and other identity provider logs for unusual login patterns, impossible travel, multiple failed login attempts, or access from unfamiliar locations/IPs. Rapid detection of compromised accounts is vital.
- Restrict Access Based on Least Privilege: Ensure that even if an identity dashboard is accessed, the compromised account has minimal permissions, limiting the scope of potential damage until the threat can be remediated.
This incident serves as a stark reminder that initial access does not equate to a successful breach if effective post-authentication controls are in place. Organizations must continuously evaluate and strengthen their security posture to counter evolving threat actor methodologies.
Related: ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign, Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk