HackMyIP
← Back to News
2026-08-24 SecurityWeek

ReliaQuest Confirms ShinyHunters Phishing Attack, Says Impact Limited

PhishingAuthenticationIncident Response

Cybersecurity firm ReliaQuest has confirmed it was targeted by hackers affiliated with the ShinyHunters group in a social engineering campaign, though the company maintains that the impact was contained and no customer data was exposed. ReliaQuest first disclosed on August 17 via a post on X that it had been tracking a widespread ShinyHunters phishing operation using domains following the ‘company.claims’ URL pattern. The firm also warned that the threat actors had expanded their tactics beyond IT and help desk impersonation to include legal team impersonation. Shortly after that post was deleted, screenshots allegedly showing access to a ReliaQuest Okta identity dashboard appeared on ShinyHunters’ leak site alongside a message taunting the security vendor.

In a statement released Monday, ReliaQuest detailed how the attack unfolded. The threat actors registered a fraudulent domain hosting a fake ReliaQuest single sign-on (SSO) phishing page, then placed phone calls to multiple ReliaQuest employees while impersonating a named internal security staff member. One employee ultimately entered their credentials on the phishing page and approved an MFA push notification on their phone, granting the attacker a brief session on the identity dashboard. Anyone looking to verify whether a suspicious domain is malicious can run a WHOIS lookup to quickly inspect registration details, ownership records, and hosting infrastructure behind lookalike URLs.

ReliaQuest emphasized that the session token granted only view-level access to the dashboard and that its existing security controls blocked every attempt by the attacker to pivot into business applications. “No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established,” the company stated, explicitly denying claims that it had been compromised by ransomware. The incident nonetheless serves as a reminder that even security vendors remain vulnerable to well-crafted vishing and phishing hybrids, and users should routinely test their own credentials with a password checker while monitoring exposure through an email breach checker to detect leaks before attackers can weaponize them.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →