threat_intelligence182 wordsRead on Arc Codex

ShinyHunters claims social engineering attack against ReliaQuest

As reported by Bleeping Computer, cybersecurity firm ReliaQuest has confirmed a social engineering attack targeting one of its employees, with threat actors impersonating members of the security team.The attack involved threat actors calling employees and attempting to trick them into accessing a fake ReliaQuest single sign-on (SSO) page hosted on a lookalike domain, reliaquest[.]claims. The attackers used the name of a real security employee during the vishing attempts. One employee fell for the ruse, entering credentials and approving an MFA push notification, granting the attacker temporary, view-only access to ReliaQuest's identity dashboard. However, device-trust controls successfully blocked further access attempts to applications.ReliaQuest stated that no systems, applications, or customer data were accessed, and the attacker's sessions were terminated, passwords revoked, and tokens reset. The extortion gang ShinyHunters claimed responsibility for the attack, sharing screenshots of a compromised Okta SSO account. ShinyHunters also stated their access was view-only and did not reach any sensitive data or systems.Bleeping Computer Source: Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.