ShinyHunters company[.]claims impersonation campaign
Campaign
Summary
Hide ▲
Show ▼
ShinyHunters is running a widespread impersonation campaign that uses company[.]claims domains to spoof help desks and IT teams, creating a repeatable credential-theft risk for targeted organizations. The operation pairs vishing with fake SSO pages and lookalike domains to capture login details. The pattern shows a broad, reusable social-engineering playbook rather than a single isolated lure.
Related Happenings
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters social engineering campaign targeting employee SSO accounts
Campaign
H score77
First: 17.07.2026 23:45
Last: 17.07.2026 23:45
Sources 1
How related:
ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing "a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."
About this happening:
The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...
ShinyHunters social engineering campaign targeting employee SSO accounts
CampaignHow related: ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing "a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."
About this happening: The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
ShinyHunters widespread Okta SSO data theft campaign
Campaign
H score43
First: 03.04.2026 20:41
Last: 03.04.2026 20:41
Sources 1
How related:
Last week, ReliaQuest's Threat Research team shared in a now-deleted post, that the ShinyHunters extortion gang was registering .claims domains to impersonate company's help desks and IT teams.
About this happening:
ShinyHunters is tied to a widespread Okta SSO identity-theft campaign that uses fake SSO pages, vishing, and lookalike .claims domains to capture credentials a...
ShinyHunters widespread Okta SSO data theft campaign
CampaignHow related: Last week, ReliaQuest's Threat Research team shared in a now-deleted post, that the ShinyHunters extortion gang was registering .claims domains to impersonate company's help desks and IT teams.
About this happening: ShinyHunters is tied to a widespread Okta SSO identity-theft campaign that uses fake SSO pages, vishing, and lookalike .claims domains to capture credentials a...
Latest development: 24.08.2026 18:17
ShinyHunters targeted ReliaQuest employees with a social engineering campaign using a fake ReliaQuest single sign-on (SSO) page hosted on the lookalike domain reliaquest.claims and a real security employee's name during vishing attempts. One employee entered credentials and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest's identity dashboard, but device-trust controls blocked further access and ReliaQuest says no customer data, applications, or systems were accessed.
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
24.08.2026 18:17 2 articles · 5h ago
ShinyHunters uses company[.]claims domains to impersonate help desks and target ReliaQuest
Campaign Scope UpdateReliaQuest says ShinyHunters was registering .claims domains to impersonate help desks and IT teams, then used reliaquest.claims and vishing to lure a ReliaQuest employee into a fake SSO page. The employee entered credentials and approved an MFA push notification, but device-trust controls limited the session to temporary view-only access and the company says no applications, systems, customer data, or persistence were reached.
Show sources
- ReliaQuest confirms failed data-theft attack after ShinyHunters breach — www.bleepingcomputer.com — 24.08.2026 18:17
- ReliaQuest confirms failed data-theft attack after ShinyHunters breach — www.bleepingcomputer.com — 24.08.2026 18:17