Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

ReliaQuest Says Device Trust Stopped ShinyHunters Data Theft

An employee entered credentials and approved MFA during a social-engineering attack, but device-trust controls reportedly blocked access to company applications.

Identity security dashboard representing a blocked cyberattack
Identity security dashboard representing a blocked cyberattack

Cybersecurity company ReliaQuest says layered identity controls stopped a social-engineering attack from reaching its business applications or customer data, even after one employee surrendered login credentials and approved a fraudulent multi-factor authentication request.

The incident was attributed to a campaign associated with the ShinyHunters data-extortion group. Attackers reportedly called employees while impersonating security personnel and directed targets to a fake single sign-on page hosted on a lookalike domain. Using the identity of a real security employee can make this type of voice-phishing attempt unusually convincing.

Credentials and MFA were not enough

One targeted employee entered credentials into the phishing page and approved an MFA push notification. That gave the attacker temporary, view-only access to an identity dashboard, according to the company's account. The attacker then attempted to open applications connected to the identity system.

Those attempts were denied because the connection did not satisfy device-trust requirements. ReliaQuest said the intruder did not reach its applications or systems and did not access customer data. The company terminated the session, revoked the exposed password and reset authentication tokens while investigating whether any other identity or persistence had been established.

ShinyHunters later displayed screenshots that appeared to show access to an employee's identity account. The evidence illustrates an important distinction between seeing an identity dashboard and successfully reaching protected company data. ReliaQuest and the alleged attackers both described the access as limited, although claims made by criminal groups should always be treated cautiously.

The defensive lesson

The incident demonstrates why MFA should not be the final security checkpoint. Push-based authentication can fail when a user is pressured by a convincing caller or overwhelmed with prompts. Device trust adds another condition by requiring access to come from an approved or properly managed computer.

Organizations can reduce similar risk by combining phishing-resistant authentication, device compliance, conditional access and short-lived sessions. Help desks should use a separate verification procedure before asking employees to take account actions. Newly registered domains that imitate a company's name should also be monitored and blocked where possible.

Employees should be trained that legitimate security teams do not need them to enter credentials into links supplied during an unsolicited call. When a questionable MFA prompt appears, the safest response is to deny it and contact the help desk through a known internal channel. The failed theft attempt shows that a single compromised factor does not have to become a full breach when additional controls remain independent and enforced.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Telecommunications network equipment representing online safety controls
Internet

PLDT Moves to Block Over 100 Sites in Child Online-Safety Push

Remote business meeting shown across multiple computer screens
Software

Microsoft Teams Adds Automatic Blocking for External Meeting Bots

WordPress website login displayed on a laptop
Cybersecurity

Hackers Target miniOrange WordPress SSO Flaws in Active Attacks