ShinyHunters Claims Breach of ReliaQuest; Security Firm Says Attack Was Thwarted

Ransomware gang lists infosec company on leak site, but ReliaQuest insists no systems or customer data were accessed

edit
By LineZotpaper
Published
Read Time3 min
Cybersecurity firm ReliaQuest and the threat actor group ShinyHunters are publicly disputing the impact of a social engineering attack on August 22, with the gang claiming it breached the company while ReliaQuest asserts the attempt was unsuccessful beyond a temporary exposure of one employee's identity.

A war of words has erupted between US security vendor ReliaQuest and the notorious hacking group ShinyHunters, which claims to have compromised the company. The dispute began when ReliaQuest researchers published a blog post about ShinyHunters using company-name ".claims" domains in social engineering campaigns. An account linked to the group responded by posting alleged screenshots of ReliaQuest's Okta dashboard on its leak site, implying it had hacked the firm, and posted a taunt asking "Who's hunting who?"

The exchange is the latest in an ongoing series of attempts by ShinyHunters to embarrass security companies, but ReliaQuest says the attack was unsuccessful beyond exposing one employee's identity. According to a post on the group's leak site, the attack allegedly involved a forgotten password for the security firm's California-based insurance company, the group's leak site membership, and a set of insider data from unnamed firms. However, the group also claimed that it had been given a deadline to pay a ransom or face further releases. But the group's broader activity includes high-profile breaches of major companies, and the group is also known for its apparent interest in security vendors, which some argue is a trend of cybercrime gangs targeting security vendors and other tech companies to gain attention.

Further context: ShinyHunters, a gray-hat hacking group, is believed to be behind a series of high-profile data breaches at major companies and a 2024 'blackmail' campaign. The group frequently targets security vendors, including those that provide data security.

What is known about the attack? Specifically, the group used an ethical hacking platform, and the group exposed campaigns involving the group's alleged theft of data from security response teams.

The distinctions between the two are significant, as the group has also claimed responsibility for security vendors.

However, a number of cyber security experts have also claimed that the attack on security vendors is an attempt to gain attention and credibility within the hacker community.

The dispute is ongoing, with ShinyHunters continuing to claim responsibility for the attack against ReliaQuest.

As of now, there is no evidence that ReliaQuest's customer data was accessed. However, the company is still investigating the attack and working to determine the full scope of the breach.

In light of the attack, ReliaQuest is urging its customers to remain vigilant and review their security logs for any suspicious activity.

§

Analysis

Why This Matters

  • This incident highlights the ongoing challenge of defending against social engineering attacks, even for cybersecurity companies themselves.
  • The public dispute between a known threat actor and a security vendor could influence how other organizations assess the credibility of breach claims.
  • The outcome may set a precedent for how security vendors respond to extortion attempts, balancing transparency with operational security.

Background

ShinyHunters is a well-known cybercriminal group with a history of high-profile data breaches, including major companies across various sectors. ReliaQuest is a US-based cybersecurity firm that provides security operations and threat intelligence services to enterprise clients. The incident began when ReliaQuest researchers published a blog post about ShinyHunters' use of ".claims" domains in social engineering campaigns, prompting the group to respond with alleged breach claims. ReliaQuest confirmed it was targeted by a social engineering attack on August 22, 2026, but stated that the attack was largely unsuccessful. The group then listed ReliaQuest on its leak site, claiming a successful breach, but evidence suggested that only one employee's identity was exposed online.

Key Perspectives

ReliaQuest: The company's response emphasizes that the attack was stopped before any systems were accessed, and that it is working with law enforcement. The technical account highlights its multi-layered security controls: device-trust verification prevented the attacker from using the phished session, and the incident response team quickly killed the session and reset credentials. The company emphasizes that no customer data was exposed and that its security posture remains intact. ShinyHunters: The threat actor group has posted screenshots allegedly showing access to ReliaQuest's Okta dashboard, claiming the attack as a victory. The screenshots are unverified but appear on the group's public leak site, which often serves as a platform for such claims. ShinyHunters has not released any stolen customer data, a discrepancy noted by SOCRadar. Security Experts: Analysts like SOCRadar have noted the lack of evidence of customer data exposure, suggesting the attack may have been more limited than initially claimed. The incident underscores that even cybersecurity firms can be vulnerable to social engineering, and the effectiveness of ReliaQuest's response will be scrutinized as a potential model for other organizations.

What to Watch

  • ReliaQuest has not disclosed whether the employee remains employed or the specific details of the identity exposed, which may be clarified in further communications.
  • Watch for any further statements from ShinyHunters or leaks of additional evidence that could change the narrative.
  • The lack of a ransom demand and the apparent failure to access systems could reduce the likelihood of significant impact, but it remains to be seen if the group escalates.
  • Other cybersecurity firms may come forward to address similar social engineering risks, potentially prompting industry-wide guidance.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.