TTO-2026-0825-003 · August 25, 2026 Social Engineering

ShinyHunters Attempts ReliaQuest Breach Via Vishing and Fake SSO Page — Device-Trust Controls Block Access After MFA Approved

reliaquest.comShinyHuntersVishing attackreliaquest.claims phishing domainFake Okta SSOMFA approvedDevice-trust controlsView-only accessNo data exfiltratedAugust 22 2026

Summary

ReliaQuest confirmed on August 24, 2026 that a vishing and phishing attack conducted against its employees on August 22 was contained after device-trust controls blocked the attacker from accessing any applications, systems, or customer data. The attack followed a pattern consistent with ShinyHunters' documented campaign targeting organizations' IT and security help desks. The attacker registered the domain reliaquest.claims and hosted a fake ReliaQuest single sign-on page behind a content delivery network. Multiple ReliaQuest employees received calls from an attacker impersonating a member of the company's own security team, who directed them to the fake SSO page. One employee entered their credentials and approved a multi-factor authentication push notification, giving the attacker temporary access to a session token for that employee's identity. ReliaQuest's device-trust controls, which require authentication to originate from a registered and trusted device, prevented the attacker from using the compromised identity session to access any internal applications. The attacker had view-only access to the identity dashboard for the duration of the session and established no persistence. No additional identities were accessed and no customer data was touched. ShinyHunters listed ReliaQuest on its dark web data leak site on August 23, publishing screenshots of the compromised Okta SSO interface. SOCRadar confirmed it found no validated data samples, ransom demand, or evidence of customer impact. Both ReliaQuest and the threat actor agree that access was limited to view-only with no persistence established.

Timeline

DateEvent
Pre-Aug 22, 2026ReliaQuest Threat Research team publishes tracking post on ShinyHunters .claims domain phishing campaign
Aug 22, 2026ShinyHunters attacks ReliaQuest via vishing — fake SSO page on reliaquest.claims
Aug 22, 2026One employee enters credentials and approves MFA push — device-trust controls block further access
Aug 23, 2026ShinyHunters lists ReliaQuest on dark web leak site — publishes Okta dashboard screenshots
Aug 23, 2026ReliaQuest and ShinyHunters trade posts on X — ReliaQuest post subsequently deleted
Aug 24, 2026ReliaQuest confirms attack — states view-only access only, no data exfiltrated, no persistence
Aug 25, 2026SOCRadar confirms no validated data samples, ransom demand, or customer impact found

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
reliaquest.com62.53Live
WarmBadge Intelligence Snapshot · Captured: August 25, 2026 UTC

Context

reliaquest.com scores 62.53 — a low-trust range score for a managed detection and response provider that markets its ability to defend enterprise security operations. The attack against ReliaQuest is operationally significant less for what ShinyHunters achieved than for what stopped them. Device-trust controls — the requirement that authentication sessions originate from enrolled, trusted devices — are the control that converted a fully successful credential and MFA compromise into a contained view-only incident. Without device-trust, the approved MFA push would have been sufficient to access applications and data. This is the third cybersecurity vendor ShinyHunters has targeted in 2026, following the Aura breach in March and the ReliaQuest attempt in August. Cybersecurity vendors are attractive targets because their systems and networks often carry access to customer environments, and because a claimed breach of a security company generates pressure on clients that a breach of an ordinary target does not.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · August 25, 2026