Key Takeaways:
- Hackers targeted security employees using a fake login web page.
- An employee approved a push notification giving attackers view access.
- The cybersecurity firm confirmed that customer data remained completely safe.
On Monday, cybersecurity firm ReliaQuest officially confirmed that the ReliaQuest phishing attack involved ShinyHunters hackers launching a targeted social engineering attack over the weekend, gaining temporary dashboard access after an employee fell for a convincing phishing ruse.
ReliaQuest Confirms Social Engineering Attack
ReliaQuest addressed the ReliaQuest phishing attack on Monday by publicly admitting it faced a clever social engineering attack over the weekend. The malicious cyber actors registered a fake domain specifically designed to host a fraudulent single sign-on login page to trap unsuspecting staff members.
The relentless attackers called multiple ReliaQuest teammates directly on the phone during the operation. They posed as actual internal security employees by name to trick busy workers into visiting the fake web page immediately.
Unfortunately, one corporate teammate fell for the clever ruse and entered a valid password. That same employee also approved a mobile push notification sent directly to their personal smartphone device.
That single operational mistake handed the aggressive threat actor a brief session on the company identity dashboard. However, the cybersecurity firm quickly discovered the breach and took immediate action to protect its digital environment.
Security Controls Block Unauthorized System Access
The cybersecurity firm explained that the hackers only obtained view-only access to the central dashboard. Crucial business applications, internal corporate systems, and sensitive customer data remained completely safe from all external harm during the ReliaQuest phishing attack.
The dangerous threat actor tried multiple times to access other core applications from the compromised dashboard. Despite these repeated malicious efforts, strong security controls consistently blocked every single unauthorized attempt to enter.
No additional user identities were accessed during the brief security incident. The company noted that no business applications were reached and no malicious persistence was ever established on their vital networks.
Security teams worked quickly to audit their systems and verify the safety of all connected devices. They ensured that no hidden digital backdoors remained active after the intruders were locked out.
Previously, the firm noted that the ShinyHunters extortion gang was registering specific domains to impersonate company help desks. An online account later shared screenshots of the dashboard before the inflammatory posts were removed.
Company Strongly Rejects Ransomware Compromise Claims
ReliaQuest firmly stated that no customer data or internal company information was touched beyond the initial login credentials. The organization quickly revoked the compromised credentials and terminated the active user session.
Company representatives emphasized that public claims suggesting the prominent firm suffered a major system compromise are entirely false. They also dismissed online rumors stating that the corporate entity was targeted by dangerous ransomware.
The recent ReliaQuest phishing attack highlights the ongoing dangers posed by sophisticated social engineering schemes targeting enterprise workers. Cybersecurity experts continue to warn organizations about the rising frequency of aggressive phone-based hacker tactics.
Investigators are carefully reviewing how the threat actors gathered employee details to execute the phone calls. Corporate leaders continue sharing vital threat intelligence to help other businesses defend against similar attacks.
Visit more of our news! CyberPro Magazine




