ShinyHunters Phishes ReliaQuest Employee via Fake SSO Page and MFA Manipulation
A ReliaQuest employee fell victim to a targeted phishing attack in which threat actors cloned the company's SSO login page and impersonated a trusted colleague to socially engineer MFA approval. This incident highlights that even cybersecurity professionals are not immune to sophisticated credential harvesting combined with MFA fatigue or push notification abuse. The attacker's ability to gain — even briefly — view-only access to an identity dashboard underscores how a single compromised account can expose sensitive organizational infrastructure. Prompt detection and containment limited the blast radius, but the incident demonstrates that phishing-resistant MFA and rigorous user training remain critical even inside security firms.
Tactical Insight
Immediate actions
- Replace push-notification MFA with phishing-resistant methods such as FIDO2/WebAuthn hardware security keys across all employee accounts.
- Deploy anti-phishing technology (e.g., browser isolation, DNS filtering, and lookalike domain detection) to block credential-harvesting pages before users can reach them.
Long-term improvements
- Establish a zero-trust identity architecture that enforces continuous verification and least-privilege access, limiting what any single compromised account can view or do.
- Implement strict SSO domain validation and certificate pinning so employees and systems reject impersonated login portals.
- Conduct regular, targeted social engineering simulations — including impersonation and MFA fatigue scenarios — tailored to high-risk roles and security staff.
Detection measures
- Enable real-time alerting on anomalous identity dashboard access, including off-hours logins, new device registrations, and bulk enumeration of user records.
- Integrate UEBA (User and Entity Behavior Analytics) to flag credential use from unexpected geolocations or device fingerprints immediately after authentication.