ReliaQuest denies ShinyHunters hacking claims

Published August 25, 2026

Cybersecurity firm ReliaQuest says attackers linked to the ShinyHunters group tricked one employee with a phone call and a fake login page, but did not break into its systems or steal customer data.

Report priority
Medium
Targets
Linux

How it works

The attackers set up a fake copy of ReliaQuest's own sign-in page, then called employees by name pretending to be ReliaQuest security staff, and one employee typed a password and approved a login prompt on their phone.

What to do

ReliaQuest says it already expired the tricked employee's password, reset every authentication factor, and cut off the attacker's session.

Technical details

Affected software: Linux

The threat actor registers a lookalike web address and builds a fake copy of ReliaQuest's sign-in page behind a content delivery network. They call several ReliaQuest employees, each time claiming to be a named ReliaQuest security staffer, trying to steer them to the fake page. One employee enters their password and approves the login prompt on their phone, handing the attacker a short, view-only look at ReliaQuest's identity dashboard, but device-trust rules stop the attacker from reaching any real application or system.

ShinyHunters ran a vishing operation against ReliaQuest, registering a lookalike domain and hosting a fake single sign-on page behind a CDN. Callers impersonated named ReliaQuest security staff to push targets toward the page. One employee submitted credentials and approved a push-based MFA prompt, giving the attacker a short-lived, read-only session in ReliaQuest's Okta-based identity dashboard.

Device-trust policy blocked the session from reaching any application or system, and ReliaQuest's incident response terminated the session and rotated the affected identity's credentials and factors. SOCRadar's independent review found the leaked screenshots support only this limited access, not the ransomware or full-compromise claims ShinyHunters made publicly.