Back to Feed
Threat IntelligenceAug 24, 2026

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest confirms ShinyHunters phishing attack targeting employee credentials.

Summary

Cybersecurity firm ReliaQuest has confirmed a phishing attack by the ShinyHunters group that compromised an employee's credentials. The attackers used a fake ReliaQuest SSO phishing page and impersonated a security employee to trick the victim into entering their password and approving a push notification. While the attackers gained brief view-only access to an identity dashboard, ReliaQuest states no customer data, business applications, or systems were compromised.

Full text

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the ‘company.claims’ URL pattern. The company also warned that the hacker gang has been expanding its social engineering tactics to include legal team impersonation alongside IT and help desk impersonation. In response to that now-deleted post, someone shared several screenshots that appeared to show access to a ReliaQuest Okta dashboard. The same screenshots were posted on ShinyHunters’ website, along with a message taunting the security firm. ReliaQuest addressed the incident on Monday, admitting it had been targeted in a social engineering attack over the weekend. According to the company, the hackers registered a fake domain and set it up to host a ReliaQuest SSO phishing page. Advertisement. Scroll to continue reading. “The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page,” the security firm explained. “One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.” ReliaQuest says the attackers obtained view-only access to the dashboard, and pointed out that its applications, systems, and customer data were not compromised. “The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place,” it noted. ReliaQuest added, “No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established. Claims that ReliaQuest was compromised or targeted by ransomware are false.” Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign Related: Personal Information Exposed in Apollo Global Data Breach Related: 1.6 Million Likely Impacted by RingCentral Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindHackers Target Zimbra Servers in Active Exploitation CampaignOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesHackers Using AI to Target Siemens PLCs in Critical US SectorsCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCareCloud Data Breach Impact Grows to 3.7 Million Individuals Latest News Hired for One Job, Judged on Another: The CISO’s Real ProblemUber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachRethinking Application Security for the AI EraIran-Linked Hackers Shut Down UK Power Plant for Four DaysTikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveVensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.WISeKey has appointed Alexander Hirsch as Group Chief Marketing Officer.UltraViolet Cyber has named Andrew Park Chief Information Security Officer.More People On The MoveExpert Insights Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • domain — company.claims

Entities

ShinyHunters (threat_actor)ReliaQuest (vendor)Okta (product)