[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBLYMR1jbtM6n9fM9eopVOPdXX7hDGqkAAo_GwzSNAxQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"85613cba-5f4c-4fdb-afc4-fd534252ae4e","shinyhunters-phishes-reliaquest-employee-via-fake-sso-page-and-mfa-manipulation","388afc03-72aa-453b-8715-6ebcdedc893f","ShinyHunters Phishes ReliaQuest Employee via Fake SSO Page and MFA Manipulation","A ReliaQuest employee fell victim to a targeted phishing attack in which threat actors cloned the company's SSO login page and impersonated a trusted colleague to socially engineer MFA approval. This incident highlights that even cybersecurity professionals are not immune to sophisticated credential harvesting combined with MFA fatigue or push notification abuse. The attacker's ability to gain — even briefly — view-only access to an identity dashboard underscores how a single compromised account can expose sensitive organizational infrastructure. Prompt detection and containment limited the blast radius, but the incident demonstrates that phishing-resistant MFA and rigorous user training remain critical even inside security firms.","**Immediate actions:**\n- Replace push-notification MFA with phishing-resistant methods such as FIDO2\u002FWebAuthn hardware security keys across all employee accounts.\n- Deploy anti-phishing technology (e.g., browser isolation, DNS filtering, and lookalike domain detection) to block credential-harvesting pages before users can reach them.\n\n**Long-term improvements:**\n- Establish a zero-trust identity architecture that enforces continuous verification and least-privilege access, limiting what any single compromised account can view or do.\n- Implement strict SSO domain validation and certificate pinning so employees and systems reject impersonated login portals.\n- Conduct regular, targeted social engineering simulations — including impersonation and MFA fatigue scenarios — tailored to high-risk roles and security staff.\n\n**Detection measures:**\n- Enable real-time alerting on anomalous identity dashboard access, including off-hours logins, new device registrations, and bulk enumeration of user records.\n- Integrate UEBA (User and Entity Behavior Analytics) to flag credential use from unexpected geolocations or device fingerprints immediately after authentication.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 14: Security Awareness and Skills Training","CIS Control 17: Incident Response Management","NIST SP 800-63B: Digital Identity Guidelines – Phishing-Resistant AAL3 Authenticators","NIST AC-2: Account Management","NIST AC-17: Remote Access","NIST IA-5: Authenticator Management","NIST SI-3: Malicious Code Protection","MITRE ATT&CK T1566.002: Spearphishing Link","MITRE ATT&CK T1621: Multi-Factor Authentication Request Generation","GDPR Article 32: Security of Processing (where EU data subjects may be involved)","published","2026-08-24T18:20:38.948482+00:00","2026-08-24T18:20:38.653+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Freliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited\u002F","reliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited-b44c65","ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]