What We Missed: Did ShinyHunters ‘Breach’ ReliaQuest?

ShinyHunters’ Taunting of ReliaQuest Raises Questions About Breach Claims

ShinyHunters, a notorious threat group, has been making headlines lately with its brazen claims of breaching major cybersecurity vendors. However, in the case of ReliaQuest, it appears that the threat group’s boasts may be more hype than substance.

ReliaQuest, a leading provider of cybersecurity services, was warned by ShinyHunters of a “widespread campaign” using spoofed company domains. In response, a ShinyHunters account on social media platform X posted screenshots that appeared to be a compromised Okta account for a ReliaQuest employee. The threat group also added ReliaQuest to its data leak site, although the listing only contained a few screenshots.

However, ReliaQuest has since disclosed that a threat actor successfully phished an employee’s credentials into a fake single sign-on (SSO) page, granting them view-only access to the SSO portal. But here’s the thing: despite having gained unauthorized access, the attacker was unable to move laterally or access applications. In other words, ReliaQuest’s security measures appear to have contained the breach.

So, was ShinyHunters’ claim of breaching ReliaQuest legitimate? It seems unlikely. The screenshots posted by ShinyHunters appear to be nothing more than a compromised Okta account, and the threat group’s boasts about breaching ReliaQuest may be little more than bragging rights.

ShinyHunters is often compared to Lapsus$, another threat group known for its low-impact breaches. In 2022 and 2023, Lapsus$ was responsible for stealing source code and gaining access to sensitive areas of networks, only to do little with the access they gained. The same appears to be true in this case: ShinyHunters’ breach claims may be more about showmanship than actual threat.

It’s worth noting that ReliaQuest’s security measures appear to have done their job, even if the attacker did gain unauthorized access. In fact, one could argue that the incident is evidence of zero trust working as intended – a security principle that assumes all users and devices are potentially malicious until proven otherwise.

The ShinyHunters-ReliaQuest incident serves as a reminder that threat group claims should be taken with a grain of salt. While it’s possible that ShinyHunters may have had some level of access to ReliaQuest’s network, the lack of actual impact suggests that their boasts may be little more than noise.

As cybersecurity professionals, we must remain vigilant and not get caught up in the hype surrounding threat group claims. Instead, we should focus on what really matters: protecting our networks and systems from actual threats, rather than getting distracted by empty boasts.


Source: Dark Reading — 2026-09-03