ReliaQuest has responded to claims of a data breach after ShinyHunters posted screenshots that appeared to show the cybersecurity firm’s Okta identity dashboard.

The company confirmed that a social engineering attack on August 22 briefly gave a threat actor access to one employee’s identity dashboard session. However, ReliaQuest said its systems, applications and customer data were not accessed.

The incident highlights why identity platforms remain a prime target for cybercriminals. A single compromised account can potentially open the door to many workplace tools.

ShinyHunters posted alleged Okta screenshots

ShinyHunters listed ReliaQuest on its leak site and shared screenshots that appeared to show applications connected to the company’s identity infrastructure.

The images reportedly included URLs associated with ReliaQuest and appeared to originate from an employee account. Still, ShinyHunters did not provide evidence showing that it had stolen data or entered other company systems.

Okta provides single sign-on services that let employees access multiple approved applications from one central portal. Depending on an organisation’s setup, that can include email, cloud storage, collaboration tools and other business systems.

As a result, access to an identity dashboard can be highly valuable to attackers, even when the visible screenshots contain little sensitive information.

ReliaQuest says access was view-only

ReliaQuest said the attackers created a lookalike domain and placed a fake company single sign-on page behind a content delivery network.

The threat actor then contacted several employees while impersonating a ReliaQuest security worker. One employee entered their password on the fake page and approved a multi-factor authentication push notification.

That action gave the attacker a temporary identity dashboard session, according to ReliaQuest.

The company said the session had view-only access and was terminated quickly. It also said the attacker tried to reach applications from the dashboard but was blocked by existing security controls.

ReliaQuest denied that it had been compromised by ransomware. It added that no customer information was accessed during the incident.

Attack mirrors wider Okta phishing campaigns

The ReliaQuest data breach claim appears linked to a wider campaign attributed to ShinyHunters. The group has reportedly used phone-based social engineering, fake login pages and multi-factor authentication abuse to target employees at other companies.

In these attacks, criminals often pose as IT support staff. They persuade targets to visit a fraudulent login page, enter their credentials and approve a sign-in request on their phone.

That combination can bypass normal password protections and give attackers a legitimate-looking session. It may also allow them to attempt access to multiple connected services without using malware.

ReliaQuest said the incident followed a familiar pattern: impersonation calls, a short-lived lookalike domain, a credential-harvesting page and attempts to register a new authenticator.

Cybersecurity firms remain valuable targets

The allegation is notable because ReliaQuest provides security operations technology to organisations managing complex threat environments.

Cybersecurity vendors often hold access to sensitive tools, customer environments and valuable operational information. That makes them attractive targets, even when attackers fail to reach protected systems.

ShinyHunters has claimed responsibility for several recent attacks and extortion campaigns. The group has also been associated with social engineering activity involving identity providers and enterprise software platforms.

For organisations, the incident reinforces the need to treat unexpected support calls and authentication prompts with caution. Employees should verify requests through trusted channels, especially before entering credentials or approving multi-factor authentication notifications.


0 responses to “ReliaQuest Says Okta Session Was Exposed in Social Engineering Attack”