Actor Profile

ShinyHunters is a notorious data extortion group known for large-scale data breaches and credential theft operations. In this incident, the group demonstrated advanced social engineering capabilities by impersonating ReliaQuest security personnel to target employees. The actor operates a data leak site where they publish evidence of compromises and extort victims. ShinyHunters has historically focused on stealing and monetizing large datasets from various organizations, often combining technical exploitation with social engineering tactics.

TTPs (Tactics, Techniques, Procedures)

The attack employed vishing (voice phishing) combined with credential harvesting via a lookalike domain (reliaquest.claims under the .claims TLD). Attackers impersonated legitimate security team members and directed victims to a fake Okta SSO page hosted behind a CDN. The operation involved T1566 (Phishing), specifically T1566.002 (Spearphishing Link) and voice-based social engineering. The threat actor successfully harvested credentials and bypassed MFA through push notification fatigue (T1621 - Multi-Factor Authentication Request Generation). However, device trust controls prevented lateral movement and application access. The campaign represents a broader pattern of ShinyHunters registering .claims domains following the pattern company[.]claims to impersonate help desks and IT teams across multiple organizations.

Targets & Patterns

In this incident, ShinyHunters specifically targeted ReliaQuest employees, likely in retaliation for the company's threat research team publicly tracking and reporting on ShinyHunters' campaign using .claims domains. The targeting was highly personalized, with attackers using the names of real ReliaQuest security employees during vishing calls to enhance credibility. The broader ShinyHunters campaign appears to target multiple organizations across sectors using the same .claims domain registration pattern, suggesting opportunistic targeting of organizations with valuable data or high-profile victims that can generate extortion leverage. The choice to target a cybersecurity firm demonstrates the group's boldness and willingness to engage in retaliatory operations against security researchers.

Historical Context

ShinyHunters is described as an "infamous data extortion group" with an established reputation for large-scale breaches. The group operates a known extortion portal where they publish evidence of compromises and leak stolen data. This incident represents an evolution in their tactics, demonstrating a shift toward targeted social engineering campaigns using lookalike domains under the .claims TLD. The attack on ReliaQuest appears retaliatory in nature, as ShinyHunters explicitly referenced ReliaQuest's previous threat intelligence reporting on the group, stating "this time the post is about you, not us." The group's willingness to publicly taunt victims on social media (X/Twitter) and engage directly with security researchers indicates a high level of confidence and established operational infrastructure.

Defensive Recommendations

  • Implement device trust and conditional access policies that verify device posture before granting application access, even with valid credentials—this control successfully prevented ShinyHunters from pivoting beyond the identity dashboard
  • Deploy anti-phishing controls that detect lookalike domains, particularly monitoring new TLD registrations (e.g., .claims) that incorporate organizational names or abbreviations
  • Enforce number matching or FIDO2-based MFA instead of push notifications to prevent MFA fatigue attacks (T1621) where users approve authentication requests without verification
  • Conduct regular security awareness training focused on vishing attacks where threat actors impersonate internal security or IT personnel, emphasizing out-of-band verification procedures
  • Monitor for anomalous SSO authentication patterns including geolocation mismatches, impossible travel, and device trust failures, with automated session termination for suspicious activity