ShinyHunters claims breach of ReliaQuest, firm says attack stopped at single identity view
ShinyHunters posted a leak alleging it accessed ReliaQuest’s Okta dashboard, but ReliaQuest says the social-engineering attempt only exposed one employee’s identity and was blocked before any systems or data were compromised.
On August 23, the ShinyHunters leak portal featured ReliaQuest as a new victim, sharing images that appeared to display the firm’s Okta dashboard. ReliaQuest’s security team acknowledged a social-engineering attempt on August 22 that succeeded in obtaining a single employee’s identity session after the victim entered credentials and approved an MFA push. However, the breach was limited to view-only access; device-trust mechanisms stopped the attackers from reaching any internal applications or data, and the compromised session was terminated and the user’s password reset.
No stolen customer information or ransom note has been found, and external monitoring services reported no validated data samples. The episode reignites a prior spat in which ReliaQuest highlighted ShinyHunters’ registration of “.claims” domains for phishing campaigns. Both parties continue to trade accusations over the true impact of the incident.
Why it matters
It shows how robust identity-security controls can limit damage from phishing attacks, even when attackers obtain valid credentials.
In this story
