ReliaQuest confirms failed data-theft attack after ShinyHunters breach
ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.
Intelligence analysis by Llama

ReliaQuest has confirmed a failed data-theft attack after hackers impersonated a member of the security team. The attacker tried to trick employees into accessing a fake SSO page, but was denied access due to security controls in place.
Imagine someone is trying to trick you into giving them your password. They might call you and pretend to be a security expert, or send you a fake email that looks like it's from a real company. If you fall for it, they might be able to see some of your information, but they won't be able to do anything else because of the security controls in place. This is what happened to ReliaQuest, a company that helps keep people's information safe.
Analysis
ReliaQuest's statement comes shortly after the infamous data extortion group 'ShinyHunters' claimed an attack on the company. In a new post on its extortion portal, ShinyHunters references ReliaQuest's previous reporting on the threat group, saying 'this time the post is about you, not us.' ReliaQuest listed on the ShinyHunters extortion page. The threat actors published evidence of access, showing that they had successfully breached ReliaQuest's Okta SSO account. We asked ReliaQuest if the disclosed incident is linked to ShinyHunters, but we have not received any additional information yet. However, ShinyHunters told BleepingComputer that their access was view only and did not reach any applications, systems, or customer data. 'No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established,' the threat actor told us. Once attackers have valid credentials, only 37% of their actions are blocked. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report. The incident highlights the importance of security controls in preventing data breaches. ReliaQuest's statement says that the threat actor hosted the phishing page on a 'lookalike domain,' which BleepingComputer found to be reliaquest.claims, and used the name of a real security employee during the vishing attempts. One of the targeted employees fell for the attacker's ruse, entered their credentials on the fake SSO page, and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest's identity dashboard. However, device-trust controls successfully blocked subsequent attempts to access applications through the dashboard, according to the company. 'The extent of the access was view-only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched,' ReliaQuest says. 'The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.' The cybersecurity firm says it terminated the attacker's sessions, revoked the exposed password, and reset all authentication tokens. The ensuing investigation found no evidence of access to other accounts, apps, or data, and no signs that the actor established persistence on ReliaQuest's systems. The firm audited its control fidelity, device trust, and on-network access since August 21 and identified no suspicious activity.
Key points
- ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team.
- The attacker tried to trick employees into accessing a fake SSO page, but was denied access due to security controls in place.
- ReliaQuest terminated the attacker's sessions, revoked the exposed password, and reset all authentication tokens.
- The company audited its control fidelity, device trust, and on-network access since August 21 and identified no suspicious activity.
ReliaQuest's security controls were able to block the attacker's attempts to access sensitive information, which is a positive sign. Additionally, the company was able to terminate the attacker's sessions and reset all authentication tokens, which should prevent any further attempts to access the system.
The fact that the attacker was able to trick one of ReliaQuest's employees into giving them their password is a concern. It highlights the importance of security awareness and training for employees, as well as the need for robust security controls to prevent data breaches.



