ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity firm ReliaQuest has confirmed that it was targeted by attackers who attempted to steal sensitive information after impersonating one of its security employees. The incident highlights the growing threat of social engineering tactics, where hackers use human psychology to gain access to systems and data.

The attack began when an individual claiming to be a member of ReliaQuest’s security team contacted multiple employees via phone, tricking them into accessing a fake single sign-on (SSO) page hosted on a content delivery network. One employee, unaware of the ruse, entered their credentials on the fake SSO page and approved a multi-factor authentication (MFA) push notification, allowing the attacker to gain temporary access to ReliaQuest’s identity dashboard.

Although the attackers were unable to access any sensitive applications or customer data due to robust security controls in place, they did manage to obtain view-only access to the dashboard. Fortunately, device-trust controls prevented further unauthorized access attempts, and the company promptly terminated the attacker’s sessions, revoked exposed passwords, and reset authentication tokens.

ReliaQuest’s response to the incident has been swift and transparent, with the company conducting a thorough investigation into the breach and auditing its control fidelity, device trust, and on-network access. The firm has confirmed that no other accounts or applications were accessed during the incident, and no signs of persistence were found on their systems.

The ShinyHunters extortion group, known for targeting companies with sophisticated social engineering tactics, claims to have been involved in the attack. In a statement, ReliaQuest said that it is tracking a widespread campaign by ShinyHunters using domains that mimic company names or abbreviations under the .claims top-level domain (TLD).

While the exact nature of the relationship between ReliaQuest and ShinyHunters remains unclear, this incident serves as a stark reminder of the evolving threat landscape. As attackers continue to innovate their tactics, companies must remain vigilant in protecting against social engineering attacks.

In light of this incident, it is essential for organizations to review their security protocols and employee awareness programs. Regular training sessions can help employees recognize and resist social engineering tactics, while robust security controls can prevent unauthorized access attempts. By staying proactive and informed, businesses can minimize the risk of such incidents occurring in the future.


Source: Bleeping Computer — 2026-08-24