ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Hacker groups and malware
- ShinyHunters
- Reported by
- 1 outlet
ReliaQuest has released details of a ShinyHunters social engineering attack which it said briefly exposed its identity dashboard, but branded claims it was compromised or targeted by ransomware as “false.”
The threat intelligence firm had been investigating a new campaign by the notorious threat group, which it said was using .claims domains in social engineering attacks.
A August 17 ReliaQuest post on X was replied to by a member of the group with what appeared to be screenshots of its Okta dashboard and the message: “Who's hunting who?"
The exchange was subsequently removed from X, but the screenshots reappeared on ShinyHunters-linked leak site on August 23, according to SOCRadar.
However, ReliaQuest subsequently hit back in a detailed write up of the incident on its site.
It stated: “Claims that ReliaQuest was compromised or targeted by ransomware are false.”
Anatomy of a Social Engineering Attack
According to the writeup, ReliaQuest was targeted by a social engineering attack on August 22.
“The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network,” it explained.
“The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”
ReliaQuest was at pains to point out that access was “view only,” and that no applications, systems or customer data were accessed, despite the threat actor's attempts.
“Our defense in depth starts from the assumption that a threat actor will eventually phish someone's account. Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate's name,” the post continued.
“We don't treat a sign-in to our identity provider as permission to do anything at all. Our controls include device trust which prevent non-ReliaQuest devices from accessing any application or systems and containment actions terminated the attacker's sessions, expired the password, and reset every authentication factor.”
ReliaQuest’s report is backed by SOCRadar’s analysis of the incident.
It said of the ShinyHunters’ posts: “These exchanges illustrate the actor’s pressure tactics and public taunting, but they do not substantiate the breach claim or demonstrate access to ReliaQuest networks.”
Reproduced in full under licence from Infosecurity Magazine. © Infosecurity Magazine.
Coverage
One outlet has carried this so far.
2026-08-25 09:30 UTC
Related stories
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The Hacker News · 2026-09-16
- Spain gets its first taste of AI-aided cyber attack
The Register · 2026-09-16
- Threat Intelligence Alone Won't Close the Exploitation Gap
The Hacker News · 2026-09-16