Infosecurity

ReliaQuest Fires Back at ShinyHunters: ‘Compromise Claims Are False’

Published

on

ReliaQuest Denies ShinyHunters Compromise Claims

ReliaQuest has pushed back hard against suggestions that it was breached or hit with ransomware, calling such claims “false.” The threat intelligence firm says a social engineering attack on August 22 briefly exposed its identity dashboard — but nothing more.

The drama began when a member of the notorious ShinyHunters group replied to a ReliaQuest post on X with screenshots of what appeared to be its Okta dashboard, alongside the taunt: “Who’s hunting who?” The exchange was quickly deleted, but the screenshots resurfaced on a ShinyHunters-linked leak site on August 23, according to SOCRadar.

ReliaQuest didn’t stay quiet. In a detailed write-up, the company stated: “Claims that ReliaQuest was compromised or targeted by ransomware are false.”

Anatomy of a Social Engineering Attack

The attack was classic social engineering, the kind that targets people, not firewalls. The threat actor registered a lookalike domain and set up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network. Then came the phone calls.

“The threat actor called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page,” the company explained. “One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”

That’s a scary moment for any security team. But ReliaQuest insists the access was “view only.” No applications, systems, or customer data were touched, despite the attacker’s efforts.

Defense in Depth: Why It Worked

ReliaQuest’s response is a masterclass in defense in depth. The company starts from the assumption that someone will eventually get phished. “Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate’s name,” the post continued.

Their controls include device trust, which blocks non-ReliaQuest devices from accessing anything, and containment actions that terminated the attacker’s sessions, expired the password, and reset every authentication factor. In other words, the attacker got a glimpse of a dashboard and nothing else.

ShinyHunters: Pressure Tactics or Real Breach?

ShinyHunters is no stranger to high-profile incidents. The group has been linked to major data breaches, including the Ticketmaster data breach and the AT&T data breach. This time, they were the subject of ReliaQuest’s investigation into a new campaign using .claims domains in social engineering attacks.

When ReliaQuest published its findings on August 17, a group member fired back with the dashboard screenshots. But SOCRadar’s analysis backs ReliaQuest’s version of events. “These exchanges illustrate the actor’s pressure tactics and public taunting, but they do not substantiate the breach claim or demonstrate access to ReliaQuest networks,” SOCRadar said.

That’s a key distinction. ShinyHunters is known for turning small wins into big headlines. A brief session on an identity dashboard is not the same as a breach — and it’s certainly not ransomware.

What This Means for Security Teams

This incident is a reminder that social engineering remains one of the most effective attack vectors. A convincing caller, a lookalike domain, and a single password entry — that’s all it takes to get a foothold. The fact that ReliaQuest caught it and contained it quickly is a testament to their controls, but it also shows how easily even security professionals can be fooled.

For organizations, the takeaways are clear:

  • Assume phishing will succeed. Build controls that limit what a compromised account can do.
  • Use device trust and conditional access to block unauthorized devices.
  • Have a rapid containment plan. ReliaQuest terminated sessions and reset credentials immediately.
  • Don’t rely on training alone. Even well-trained employees can be deceived.

ReliaQuest’s response also highlights the importance of transparency. Instead of staying silent, they published a detailed account of what happened, what was accessed, and what wasn’t. That’s the kind of honesty that builds trust — even in the middle of a public spat with a notorious threat group.

The Bottom Line

ShinyHunters may have scored a small victory by getting a teammate to enter a password. But the company’s defenses held. No data was stolen, no systems were accessed, and no ransomware was deployed. The claims of a compromise are, in ReliaQuest’s words, “false.”

Still, this incident is a valuable case study. It shows how social engineering works in practice, and how a well-designed security posture can turn a potential disaster into a minor incident. For anyone in cybersecurity, it’s a reminder that the human element is often the weakest link — and the most important one to protect.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version