ReliaQuest employee data leaked in ShinyHunters phishing hack

Published August 25, 2026

ReliaQuest, a cybersecurity company, says one employee was tricked by a fake login page and briefly gave attackers access to an internal dashboard. The ShinyHunters group only got view-only access and could not reach customer data or other company systems.

Report priority
Medium
Targets
Okta+1 more

How it works

Attackers built a fake ReliaQuest login page and called employees by phone, naming real security staff to sound convincing, until one employee typed in a password and approved a login prompt on their phone.

What to do

Anyone with questions can review ReliaQuest's own public statement on the incident.

Technical details

Affected software: Okta, ShinyHunters

Attackers register a fake web address built to host a copy of ReliaQuest's login page. They call ReliaQuest employees, naming real security staff by name to steer them toward the fake page. One employee enters their password and approves a push notification on their phone, handing the attacker a short session inside the company's identity dashboard. The attacker tries to use that access to reach other business applications but is blocked each time by ReliaQuest's security controls.

ShinyHunters ran a phone-based social engineering campaign using domains following a company.claims pattern to host fake single sign-on pages. Attackers called ReliaQuest employees, impersonating named security staff to steer them to a fake SSO page for the company's identity provider. One employee entered credentials and approved a push MFA prompt, giving the attacker a session on ReliaQuest's Okta-connected dashboard with view-only access. ReliaQuest says follow-on attempts to reach other business applications from that session were blocked by existing access controls, and no persistence, customer data, or business systems were compromised.