ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
ReliaQuest confirmed that one of its employees fell victim to a social engineering attack that provided attackers with a password and temporary access to the company's identity system. Extortion group ShinyHunters subsequently posted screenshots on its leak site, claiming responsibility and taunting the cybersecurity firm over the breach. The incident followed an earlier exchange between ShinyHunters and ReliaQuest's threat research team on social media.
ReliaQuest has confirmed that threat actor ShinyHunters exploited a phishing attack against an employee to gain access to a dashboard within the company's systems. The company claims that the scope of the breach was limited, though the specific data accessed or exposed was not detailed in the report.
Scammers are leveraging fake TikTok login pages and fraudulent verification alerts to deceive users into revealing their account credentials. Security professionals should be aware of this phishing campaign targeting TikTok users, as attackers use convincing replicas of official login and verification interfaces to compromise accounts.
Attackers are deploying counterfeit Microsoft security scanners that fabricate threats and convince users to disable their legitimate antivirus software, leaving systems vulnerable to further compromise. Once victims uninstall their protections, the scammers redirect them into refund fraud schemes, exploiting the deception to extract payment.
Threat actor Doubloon Dredger is leveraging Notion, a legitimate productivity platform, alongside malicious PDFs to conduct authentication token harvesting attacks targeting Microsoft credentials. This technique exploits user trust in commonly-used services to compromise account access and enable lateral movement within targeted organizations.