ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A Notorious Hackers’ Group Targeted ReliaQuest, but the Impact Was Minimal, According to the Company

Cybersecurity firm ReliaQuest has confirmed that it was targeted by hackers affiliated with the notorious ShinyHunters group. The attackers attempted to gain unauthorized access to ReliaQuest’s systems using a sophisticated social engineering tactic. However, in a rare instance of good news for cybersecurity, the impact of the attack appears to have been limited.

ReliaQuest first revealed on August 17 that it had been tracking a widespread phishing campaign by ShinyHunters involving domains with the “company.claims” URL pattern. The hackers were expanding their tactics to include impersonating legal teams alongside IT and help desk employees, making the attacks even more convincing. This is where the situation took a concerning turn – someone shared screenshots that appeared to show access to ReliaQuest’s Okta dashboard on ShinyHunters’ website.

ReliaQuest admitted in a statement that it had been targeted in a social engineering attack over the weekend. The hackers registered a fake domain and set up a phishing page that mimicked ReliaQuest’s SSO (single sign-on) login process. They then contacted multiple ReliaQuest employees, posing as security employees by name to trick them into accessing the fake page. One employee entered their password and approved a push notification on their phone, giving the attackers brief access to the identity dashboard.

Fortunately for ReliaQuest, its security controls prevented the hackers from gaining more than view-only access to the dashboard. The attackers were unable to access any business applications, customer data, or additional identities beyond the compromised employee’s login credentials. In other words, despite the sophisticated attack, the company’s systems and customer data remained safe.

ReliaQuest’s swift response to the incident is a testament to its robust security measures and proactive approach to cybersecurity. The company’s statement effectively debunked claims that it was compromised or targeted by ransomware, emphasizing that no additional identities were accessed, no business applications were reached, and no persistence was established.

The ShinyHunters group has been making headlines with their creative social engineering tactics and high-profile targets. This latest incident serves as a reminder of the importance of employee education and awareness in preventing such attacks. It’s essential for companies to invest in robust security measures and regularly test their employees’ vulnerability to phishing attempts.

As cybersecurity professionals, we must continue to learn from these incidents and develop effective strategies to combat the evolving threats posed by sophisticated hackers like ShinyHunters. The limited impact of this attack on ReliaQuest is a silver lining that we can draw inspiration from – with strong security measures in place, even the most cunning attacks can be mitigated.

To prevent similar incidents, it’s crucial for employees to remain vigilant and report any suspicious activity immediately. Companies should also prioritize regular employee training programs, phishing simulations, and robust security protocols to safeguard their systems and customer data. By staying proactive and informed, we can reduce the risk of successful social engineering attacks and keep our networks secure.


Source: SecurityWeek — 2026-08-24