ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest, a cybersecurity firm, has confirmed that it was targeted by hackers affiliated with the notorious ShinyHunters group. However, despite the sophistication of the attack, the company claims that its impact was limited to gaining view-only access to one employee’s Okta dashboard.

The incident began when ReliaQuest noticed a widespread phishing campaign launched by ShinyHunters using domains with the ‘company.claims’ URL pattern. The hackers attempted to trick employees into accessing a fake login page, where they would be prompted to enter their credentials and approve a push notification on their phone. In this case, one employee fell victim to the ruse, allowing the attackers to gain brief access to ReliaQuest’s identity dashboard.

ShinyHunters, known for their cunning social engineering tactics, have been expanding their operations in recent months. They have been using various impersonation techniques, including posing as IT and help desk employees, as well as legal team members. The group has also been registering fake domains and setting up phishing pages to trick victims into handing over sensitive information.

ReliaQuest’s Okta dashboard is a single sign-on (SSO) system that allows employees to access multiple applications and systems with a single set of credentials. While the attackers were able to gain view-only access to the dashboard, they were unable to move laterally or access any business-critical applications or customer data.

The company has assured its customers that no additional identities were accessed, no business applications were reached, and no customer or ReliaQuest data was compromised beyond login credentials. The incident highlights the importance of robust security controls and employee education in preventing social engineering attacks.

ReliaQuest’s experience serves as a reminder that even well-established cybersecurity firms can fall victim to sophisticated attacks. However, by having robust security measures in place and being proactive in monitoring for potential threats, companies can minimize the impact of such incidents.

As a takeaway from this incident, it is essential for organizations to prioritize employee education and awareness about social engineering tactics, as well as implement robust security controls that include multi-factor authentication, regular security updates, and continuous monitoring. By doing so, they can reduce their vulnerability to these types of attacks and minimize the risk of data breaches.


Source: SecurityWeek — 2026-08-24