ShinyHunters’ Taunting of ReliaQuest Raises Questions About Breach Claims
In a bizarre series of events, ShinyHunters, a notorious threat group, publicly boasted about breaching ReliaQuest, a cybersecurity vendor. However, closer examination reveals that the claims may be more bluster than substance. What exactly happened? And what does it say about the effectiveness of ReliaQuest’s security measures?
Last week, ReliaQuest warned of a “widespread ShinyHunters campaign” using spoofed company domains in a now-deleted post on social media platform X. In response, an account associated with ShinyHunters chimed in, posting screenshots that appeared to be a compromised Okta account for a ReliaQuest employee. The threat group also added ReliaQuest to its data leak site, though the listing only contained a few screenshots.
But here’s where things get murky. Later that day, ReliaQuest disclosed that a threat actor had successfully phished an employee who entered their credentials into a fake single sign-on (SSO) page. However, the vendor claimed that the attacker had only view-only access to its SSO portal and was unable to access applications or move laterally within the network.
So, was ReliaQuest really breached? In one sense, yes – an attacker did gain unauthorized access to the company’s Okta account. But in another sense, no – the attacker’s activities were largely contained, and they were ultimately unable to do any significant harm.
This raises questions about ShinyHunters’ motivations. Are they trying to make a name for themselves by claiming high-profile breaches, even if they don’t actually achieve much? Or are they genuinely attempting to exploit vulnerabilities in ReliaQuest’s security?
Alex Culafi, co-host of Dark Reading’s “What We Missed” podcast, notes that ShinyHunters’ behavior is reminiscent of another threat group, Lapsus$. In 2022 and 2023, Lapsus$ was known for carrying out low-impact breaches where they would steal source code or gain access to sensitive systems, only to take screenshots and brag about their exploits.
Culafi suggests that ShinyHunters’ actions may be following a similar playbook. While it’s possible that the threat group is trying to make a bigger splash with its claims, it’s also possible that they’re simply trying to prove that even highly secure companies like ReliaQuest can be breached – at least in theory.
The incident does provide some insight into the effectiveness of ReliaQuest’s security measures. Despite the attacker gaining unauthorized access to the Okta account, they were ultimately unable to do any significant harm. This may be evidence of zero-trust working as intended – even if an attacker gains access to sensitive systems, they should still be unable to move freely within the network.
In conclusion, while ShinyHunters’ claims about breaching ReliaQuest may be exaggerated, the incident does highlight the importance of robust security measures and vigilant monitoring. It also serves as a reminder that even highly secure companies can fall victim to social engineering attacks – but it’s how they respond to those incidents that truly matters.
To stay ahead of threats like ShinyHunters, organizations should prioritize employee education and awareness programs, as well as invest in robust security measures such as multi-factor authentication and zero-trust architectures. By doing so, they can minimize the risk of a breach – even if it’s just a low-impact one – and ensure that their systems remain secure, even in the face of determined attackers.
Source: Dark Reading — 2026-09-03