On 22 August 2026, ReliaQuest, the managed detection and response (MDR) provider that sells threat intelligence and incident response services to enterprise security teams, became the target of the exact social engineering technique it had spent the previous week warning its own customers about. Five days earlier, ReliaQuest's threat research team had posted publicly about a widespread ShinyHunters campaign that registered lookalike domains, pairing target companies' names with the word "claims" as a top-level domain, to impersonate the help desks, IT teams and legal departments of the organisations being targeted. The extortion group read the warning, then built one for ReliaQuest itself.
The attackers registered a lookalike domain built on that same naming pattern and set up a convincing single sign-on page behind a content delivery network to disguise its true origin. They then called several ReliaQuest employees directly, each time using the real name of a specific member of the company's own security team to add credibility, and talked them toward the fake login page.
One employee entered their password on the cloned page and, when prompted, approved the multi-factor authentication push sent to their phone. That single approval handed the attackers a live session inside ReliaQuest's identity dashboard, the control plane that manages employee access across the company's internal systems. From there they attempted to reach ReliaQuest's business applications. Every attempt was blocked, not because anyone verified whether the access was legitimate, but because the requesting device had never been registered as trusted.
Exactly how far the intrusion went is disputed. ShinyHunters published screenshots on its extortion site claiming deeper access, including what appears to be a compromised Okta single sign-on account, and taunted the researchers directly, asking "who's hunting who?" ReliaQuest maintains the access was view-only, that no customer data, other identities or business applications were reached, and that no persistence was established. Both statements can be true at once. The login succeeded, and the blast radius was contained by a control that had nothing to do with confirming who was actually logging in.
The defences that failed here were not weak by conventional standards. ReliaQuest is a company whose business is detecting and responding to exactly this kind of intrusion, and its own staff had publicly warned about this specific tactic five days before it was used against them. Multi-factor authentication was in place. Device-trust segmentation was in place, and it is the only reason this story is a near miss rather than a full breach. What was missing was a way to confirm, at the moment the login was attempted, that the person requesting it was the person it claimed to be, on a device and channel the attacker could not also influence. A push notification sent to the same phone the attacker is coaching the target through is not an independent channel. It is a formality a skilled caller can talk someone through in real time.
A credential login combined with an MFA approval into an internal identity system is an execution event under GoFirm's model. Before that session is granted, a confirmation request goes out over a separate channel to the named authority for that account, the actual employee whose identity is being used, on their own registered device, requiring a biometric confirmation independent of whatever call or page is active in that moment. If an attacker is on the phone coaching an employee through a fake login while impersonating a colleague, the confirmation request still goes to the real employee's own device, regardless of what page is open in front of them. No confirmation, no session. The dashboard access the call was designed to obtain never opens.
This would have stopped the attack at the exact point the employee entered a password and accepted a prompt, not two steps later when a device-trust rule happened to catch the follow-on attempts. A vishing call, however convincing and however accurately it names its target's real colleagues, cannot produce a biometric confirmation on that employee's own device through a channel the caller does not control. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Toulas, B. 2026. ReliaQuest confirms failed data-theft attack after ShinyHunters breach. BleepingComputer, 24 August 2026. E
2. Markovic, S. 2026. ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack. Help Net Security, 25 August 2026.
3. ReliaQuest. 2026. Threat Spotlight: Social Engineering Attempt Against ReliaQuest, What We Found. ReliaQuest Blog, 23 August 2026.
Back to Blog
Case Studies·4 min read
ReliaQuest published a warning about ShinyHunters' fake login pages. A week later, its own employee walked into one.
By GoFirm
