Fizzle: ShinyHunters’ claimed attack on ReliaQuest went nowhere: ReliaQuest

In Data Breach News
August 24, 2026

DataBreaches.net reports:

Yesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/enduser/settings.

ReliaQuest did not reply to DataBreaches’ email inquiry, but they have published an entire blog post responding to the claims. Without naming ShinyHunters, they write, in part:

Our defense in depth starts from the assumption that a threat actor will eventually phish someone’s account. Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate’s name. We don’t treat a sign-in to our identity provider as permission to do anything at all. Our controls include device trust which prevent non-ReliaQuest devices from accessing any application or systems and containment actions terminated the attacker’s sessions, expired the password, and reset every authentication factor.

The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network. The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.

The extent of the access was view only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched. The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.

Read ReliaQuest’s blog post.