A war of words has erupted between US security vendor ReliaQuest and the notorious hacking group ShinyHunters, which claims to have compromised the company. The dispute began when ReliaQuest researchers published a blog post about ShinyHunters using company-name ".claims" domains in social engineering campaigns. An account linked to the group responded by posting alleged screenshots of ReliaQuest's Okta dashboard on its leak site, implying it had hacked the firm, and posted a taunt asking "Who's hunting who?"
The exchange is the latest in an ongoing series of attempts by ShinyHunters to embarrass security companies, but ReliaQuest says the attack was unsuccessful beyond exposing one employee's identity. According to a post on the group's leak site, the attack allegedly involved a forgotten password for the security firm's California-based insurance company, the group's leak site membership, and a set of insider data from unnamed firms. However, the group also claimed that it had been given a deadline to pay a ransom or face further releases. But the group's broader activity includes high-profile breaches of major companies, and the group is also known for its apparent interest in security vendors, which some argue is a trend of cybercrime gangs targeting security vendors and other tech companies to gain attention.
Further context: ShinyHunters, a gray-hat hacking group, is believed to be behind a series of high-profile data breaches at major companies and a 2024 'blackmail' campaign. The group frequently targets security vendors, including those that provide data security.
What is known about the attack? Specifically, the group used an ethical hacking platform, and the group exposed campaigns involving the group's alleged theft of data from security response teams.
The distinctions between the two are significant, as the group has also claimed responsibility for security vendors.
However, a number of cyber security experts have also claimed that the attack on security vendors is an attempt to gain attention and credibility within the hacker community.
The dispute is ongoing, with ShinyHunters continuing to claim responsibility for the attack against ReliaQuest.
As of now, there is no evidence that ReliaQuest's customer data was accessed. However, the company is still investigating the attack and working to determine the full scope of the breach.
In light of the attack, ReliaQuest is urging its customers to remain vigilant and review their security logs for any suspicious activity.