ShinyHunters used a fake ReliaQuest Okta login page and phone impersonation to gain temporary view-only access

ReliaQuest says attackers pretending to be its security staff tricked an employee into logging into a fake single sign-on page and approving a multi-factor authentication prompt. The phishing page was hosted on a lookalike .claims domain and the actor reportedly gained temporary view-only access to a ReliaQuest Okta identity dashboard, but device-trust controls blocked access to downstream applications, customer data, and persistence.
Why it matters: This shows ShinyHunters-style vishing and fake help-desk lures are actively being used even against security companies, and a single approved MFA prompt can still grant initial access. Organizations should warn staff about calls directing them to new login pages, review help-desk verification procedures, and harden identity systems with device-trust and token/session revocation controls.

Sources

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
Eduard Kovacs 2026.08.24 99% relevant
This article is a direct update on the same incident, adding ReliaQuest’s formal confirmation that a phishing domain and phone impersonation tricked one employee into entering a password and approving an MFA push, resulting in brief view-only Okta dashboard access but no access to business apps, customer data, or persistence.
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Bill Toulas 2026.08.24 100% relevant
This article establishes a distinct incident at ReliaQuest in which a ShinyHunters-linked vishing and phishing attempt achieved limited Okta dashboard access but failed to reach applications or customer data.
← Back to all stories