Summary
ReliaQuest confirmed on August 24, 2026 that a vishing and phishing attack conducted against its employees on August 22 was contained after device-trust controls blocked the attacker from accessing any applications, systems, or customer data. The attack followed a pattern consistent with ShinyHunters' documented campaign targeting organizations' IT and security help desks. The attacker registered the domain reliaquest.claims and hosted a fake ReliaQuest single sign-on page behind a content delivery network. Multiple ReliaQuest employees received calls from an attacker impersonating a member of the company's own security team, who directed them to the fake SSO page. One employee entered their credentials and approved a multi-factor authentication push notification, giving the attacker temporary access to a session token for that employee's identity. ReliaQuest's device-trust controls, which require authentication to originate from a registered and trusted device, prevented the attacker from using the compromised identity session to access any internal applications. The attacker had view-only access to the identity dashboard for the duration of the session and established no persistence. No additional identities were accessed and no customer data was touched. ShinyHunters listed ReliaQuest on its dark web data leak site on August 23, publishing screenshots of the compromised Okta SSO interface. SOCRadar confirmed it found no validated data samples, ransom demand, or evidence of customer impact. Both ReliaQuest and the threat actor agree that access was limited to view-only with no persistence established.
Timeline
| Date | Event |
|---|---|
| Pre-Aug 22, 2026 | ReliaQuest Threat Research team publishes tracking post on ShinyHunters .claims domain phishing campaign |
| Aug 22, 2026 | ShinyHunters attacks ReliaQuest via vishing — fake SSO page on reliaquest.claims |
| Aug 22, 2026 | One employee enters credentials and approves MFA push — device-trust controls block further access |
| Aug 23, 2026 | ShinyHunters lists ReliaQuest on dark web leak site — publishes Okta dashboard screenshots |
| Aug 23, 2026 | ReliaQuest and ShinyHunters trade posts on X — ReliaQuest post subsequently deleted |
| Aug 24, 2026 | ReliaQuest confirms attack — states view-only access only, no data exfiltrated, no persistence |
| Aug 25, 2026 | SOCRadar confirms no validated data samples, ransom demand, or customer impact found |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| reliaquest.com | 62.53 | ✓ | ✓ | ✓ | Live |
Context
reliaquest.com scores 62.53 — a low-trust range score for a managed detection and response provider that markets its ability to defend enterprise security operations. The attack against ReliaQuest is operationally significant less for what ShinyHunters achieved than for what stopped them. Device-trust controls — the requirement that authentication sessions originate from enrolled, trusted devices — are the control that converted a fully successful credential and MFA compromise into a contained view-only incident. Without device-trust, the approved MFA push would have been sufficient to access applications and data. This is the third cybersecurity vendor ShinyHunters has targeted in 2026, following the Aura breach in March and the ReliaQuest attempt in August. Cybersecurity vendors are attractive targets because their systems and networks often carry access to customer environments, and because a claimed breach of a security company generates pressure on clients that a breach of an ordinary target does not.
The Trust Observatory · thetrustobservatory.com · August 25, 2026