Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Burnham ups the ante in fight against Russia — and leaves Merz in the shade – POLITICO

    August 24, 2026

    Rupert Lowe set to be paid as much for divisive posts on Elon Musk’s X as for being MP | Rupert Lowe

    August 24, 2026

    The best early Labor Day Garmin watch deals: Gear up for marathon training for less

    August 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Burnham ups the ante in fight against Russia — and leaves Merz in the shade – POLITICO
    • Rupert Lowe set to be paid as much for divisive posts on Elon Musk’s X as for being MP | Rupert Lowe
    • The best early Labor Day Garmin watch deals: Gear up for marathon training for less
    • ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
    • Crypto Organizations Oppose Illinois Digital Asset Tax in Court
    • Common medications may change your gut for years
    • Remembering the ‘Visionary’ Author of Pennsylvania’s Environmental Rights Amendment
    • WATCH: $17.5B US Gulf Coast LNG project taking shape as Woodside pushes toward 2029 start-up
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ReliaQuest confirms failed data-theft attack after ShinyHunters breach

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team.

    In a statement over the weekend, ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing “a fake ReliaQuest single sign-on (SSO) page behind a content delivery network.”

    Last week, ReliaQuest’s Threat Research team shared in a now-deleted post, that the ShinyHunters extortion gang was registering .claims domains to impersonate company’s help desks and IT teams.

    image

    “ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization’s name or abbreviation under the .claims TLD,” read the company’s post on X.

    Yesterday, a newly-created X account believed to be linked to the threat actors replied to the post, stating “Who’s hunting who ?,” sharing screenshots of what appeared to be a compromised Okta SSO account for a ReliaQuest employee.

    Soon after, ShinyHunters published the same screenshots in a new entry on their data data leak site.

    Both ReliaQuest’s and the alleged threat actor’s posts were later taken down from X. 

    According to the company, the threat actor hosted the phishing page on a “lookalike domain,” which BleepingComputer learned from sources was reliaquest.claims, and used the name of a real security employee during the vishing attempts.

    One of the targeted employees fell for the attacker’s ruse, entered their credentials on the fake SSO page, and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest’s identity dashboard.

    However, device-trust controls successfully blocked subsequent attempts to access applications through the dashboard, according to the company.

    “The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched,” ReliaQuest says.

    “The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.”

    The cybersecurity firm says it terminated the attacker’s sessions, revoked the exposed password, and reset all authentication tokens.

    The ensuing investigation found no evidence of access to other accounts, apps, or data, and no signs that the actor established persistence on ReliaQuest’s systems.

    The firm audited its control fidelity, device trust, and on-network access since August 21 and identified no suspicious activity.

    ShinyHunters claims the attack

    ReliaQuest’s statement comes shortly after the infamous data extortion group ‘ShinyHunters’ claimed an attack on the company.

    In a new post on its extortion portal, ShinyHunters references ReliaQuest’s previous reporting on the threat group, saying “this time the post is about you, not us.”

    Post on the ShinyHunters extortion page
    ReliaQuest listed on the ShinyHunters extortion page
    Source: BleepingComputer

    The threat actors published evidence of access, showing that they had successfully breached ReliaQuest’s Okta SSO account.

    We asked ReliaQuest if the disclosed incident is linked to ShinyHunters, but we have not received any additional information yet.

    However, ShinyHunters told BleepingComputer that their access was view only and did not reach any applications, systems, or customer data.

    “No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user’s login credentials, and no persistence was established,” the threat actor told us.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attack breach Confirms datatheft failed ReliaQuest ShinyHunters
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

    Microsoft Teams now lets admins block external bots from meetings

    Microsoft: August updates break printing, PDF export in WPF apps

    U.S. Military Kills 2 People in Attack on Boat in Pacific

    Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

    CISA orders urgent patching of actively exploited Zimbra flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Burnham ups the ante in fight against Russia — and leaves Merz in the shade – POLITICO

    August 24, 2026

    Rupert Lowe set to be paid as much for divisive posts on Elon Musk’s X as for being MP | Rupert Lowe

    August 24, 2026

    The best early Labor Day Garmin watch deals: Gear up for marathon training for less

    August 24, 2026

    ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

    August 24, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Burnham ups the ante in fight against Russia — and leaves Merz in the shade – POLITICO

    August 24, 2026

    Rupert Lowe set to be paid as much for divisive posts on Elon Musk’s X as for being MP | Rupert Lowe

    August 24, 2026

    The best early Labor Day Garmin watch deals: Gear up for marathon training for less

    August 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.