ShinyHunters and ReliaQuest trade blows over claimed breach
Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got
ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew's social engineering attack only got as far as one employee identity before its defenses slammed the door.
The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site on August 23, claiming the corporation as its latest victim.
The listing, seen by The Register, links to screenshots the gang claims show access to ReliaQuest's Okta dashboard. It did not publish any stolen customer data, however, and SOCRadar said it had found no validated data samples, ransom demand, or evidence of customer impact.
There had already been some public needle between the two sides. Days earlier, ReliaQuest researchers posted about ShinyHunters registering company-name “.claims” domains as part of its social engineering campaigns. An account associated with the crew responded with...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE