Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShinyHunters company[.]claims impersonation campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

ShinyHunters is running a widespread impersonation campaign that uses company[.]claims domains to spoof help desks and IT teams, creating a repeatable credential-theft risk for targeted organizations. The operation pairs vishing with fake SSO pages and lookalike domains to capture login details. The pattern shows a broad, reusable social-engineering playbook rather than a single isolated lure.

Related Happenings

ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations

Campaign
H score34 First: 29.07.2026 20:54 Last: 29.07.2026 20:54 Sources 1

About this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...

ShinyHunters social engineering campaign targeting employee SSO accounts

Campaign
H score77 First: 17.07.2026 23:45 Last: 17.07.2026 23:45 Sources 1

How related: ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing "a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."

About this happening: The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...

The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster

Threat Actor Meta
H score14 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...

ShinyHunters widespread Okta SSO data theft campaign

Campaign
H score43 First: 03.04.2026 20:41 Last: 03.04.2026 20:41 Sources 1

How related: Last week, ReliaQuest's Threat Research team shared in a now-deleted post, that the ShinyHunters extortion gang was registering .claims domains to impersonate company's help desks and IT teams.

About this happening: ShinyHunters is tied to a widespread Okta SSO identity-theft campaign that uses fake SSO pages, vishing, and lookalike .claims domains to capture credentials a...

Latest development: 24.08.2026 18:17

ShinyHunters targeted ReliaQuest employees with a social engineering campaign using a fake ReliaQuest single sign-on (SSO) page hosted on the lookalike domain reliaquest.claims and a real security employee's name during vishing attempts. One employee entered credentials and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest's identity dashboard, but device-trust controls blocked further access and ReliaQuest says no customer data, applications, or systems were accessed.

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 24.08.2026 18:17 2 articles · 5h ago

    ShinyHunters uses company[.]claims domains to impersonate help desks and target ReliaQuest

    Campaign Scope Update

    ReliaQuest says ShinyHunters was registering .claims domains to impersonate help desks and IT teams, then used reliaquest.claims and vishing to lure a ReliaQuest employee into a fake SSO page. The employee entered credentials and approved an MFA push notification, but device-trust controls limited the session to temporary view-only access and the company says no applications, systems, customer data, or persistence were reached.

    Show sources