Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

August 26, 2026

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

August 26, 2026

Four in Five AI Tools Run with No IT Oversight, Research Finds

August 26, 2026
Facebook X (Twitter) Instagram
Wednesday, August 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
News

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

Team-CWDBy Team-CWDAugust 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


ReliaQuest has released details of a ShinyHunters social engineering attack which it said briefly exposed its identity dashboard, but branded claims it was compromised or targeted by ransomware as “false.”

The threat intelligence firm had been investigating a new campaign by the notorious threat group, which it said was using .claims domains in social engineering attacks.

A August 17 ReliaQuest post on X was replied to by a member of the group with what appeared to be screenshots of its Okta dashboard and the message: “Who’s hunting who?”

The exchange was subsequently removed from X, but the screenshots reappeared on ShinyHunters-linked leak site on August 23, according to SOCRadar.

Read more on ShinyHunters: ShinyHunters Escalates Canvas Extortion with School-by-School Ransom Campaign

However, ReliaQuest subsequently hit back in a detailed write up of the incident on its site.

It stated: “Claims that ReliaQuest was compromised or targeted by ransomware are false.”

Anatomy of a Social Engineering Attack

According to the writeup, ReliaQuest was targeted by a social engineering attack on August 22.

“The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network,” it explained.

“The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”

ReliaQuest was at pains to point out that access was “view only,” and that no applications, systems or customer data were accessed, despite the threat actor’s attempts.

“Our defense in depth starts from the assumption that a threat actor will eventually phish someone’s account. Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate’s name,” the post continued.

“We don’t treat a sign-in to our identity provider as permission to do anything at all. Our controls include device trust which prevent non-ReliaQuest devices from accessing any application or systems and containment actions terminated the attacker’s sessions, expired the password, and reset every authentication factor.”

ReliaQuest’s report is backed by SOCRadar’s analysis of the incident.

It said of the ShinyHunters’ posts: “These exchanges illustrate the actor’s pressure tactics and public taunting, but they do not substantiate the breach claim or demonstrate access to ReliaQuest networks.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Next Article Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
Team-CWD
  • Website

Related Posts

News

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

August 26, 2026
News

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

August 26, 2026
News

Tortoiseshell Expands Toolset With New Backdoor, SSH Tunnel

August 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Children and chatbots: What parents should know

January 23, 2026

A phishing attack that doesn’t steal your password

June 15, 2026

How to tell if a voice call is AI or not

February 23, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.