Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmed

ReliaQuest blocks ShinyHunters vishing attack with device-trust controls

ReliaQuest · Technology · United States · August 24, 2026

What happened

Cybersecurity company ReliaQuest disclosed a failed social engineering attack by the ShinyHunters extortion group, reported August 24, 2026. Attackers impersonated members of ReliaQuest's own security team by phone and directed employees to a fake single sign-on page on the lookalike domain 'reliaquest.claims'. One employee entered credentials and approved an MFA push, but device-trust controls stopped the attackers from reaching any application, and no customer data was touched.

How the deception worked

The callers claimed to be from the company's internal security team, a pretext with unusual authority inside a security firm, and sent the target to a domain chosen to look like a ReliaQuest property. The employee entered credentials and approved the push notification, which handed the attackers a session. That session yielded only view-only visibility of the identity dashboard, because device-trust policy required a managed, enrolled device before any application would open. ReliaQuest then terminated sessions, revoked the exposed password and reset authentication tokens, finding no persistence or lateral movement.

AI involvement · Unknown

ReliaQuest did not state whether synthetic voice was used on the calls.

The control that would have caught it· our reading, not a claim from the sources

Device-trust enforcement is what converted a successful credential phish into a contained non-event; identity compromise should never be sufficient on its own for application access.

Sources (1)

  1. ReliaQuest confirms failed data-theft attack after ShinyHunters breach
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.