Threat Intelligence Brief
Curated summary with source attribution
Source: securityweek.com
Threat Risk: Medium
Victim: ReliaQuest
Incident: Phishing and social engineering attack resulting in unauthorized identity dashboard access.
Impact: Unauthorized view-only access to a single user’s identity dashboard with no data exfiltration.
Attacker: ShinyHunters
Analysis: The attack utilized a multi-stage approach combining fake domains and impersonation calls to trick employees into bypassing MFA. By leveraging a phishing page and phone-based social engineering, the actor gained brief, view-only access to an identity dashboard. Strong internal security controls ultimately prevented the actor from escalating privileges or accessing sensitive customer data.
Recommendations: Deploy phishing-resistant MFA such as FIDO2/WebAuthn to mitigate session hijacking; Conduct simulation training focusing on impersonation tactics from legal and IT teams; Implement proactive monitoring for newly registered domains mimicking corporate SSO patterns
Source: SecurityWeek
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source