Threat Intelligence Brief
Curated summary with source attribution
Source: bleepingcomputer.com
Threat Risk: Medium
Victim: Managed Security Service Providers
Incident: Targeted social engineering attack resulting in temporary unauthorized view-only access to an identity dashboard.
Impact: Minimal; device-trust controls prevented access to applications and customer data.
Attacker: ShinyHunters
Analysis: ShinyHunters utilized a combination of vishing and phishing via ‘.claims’ domains to target ReliaQuest employees. While the attackers bypassed MFA for one user, strict device-trust controls prevented lateral movement into sensitive applications. This event underscores the vulnerability of identity providers to targeted social engineering despite the presence of MFA.
Recommendations: Implement hardware-based MFA (FIDO2/WebAuthn) to mitigate push-notification fatigue and phishing; Enforce strict device-trust and conditional access policies to block unauthorized hardware; Conduct targeted vishing simulation training for high-privilege employees
Source: BleepingComputer
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source