American cyber security firm ReliaQuest has shared details of an attempted social engineering attack targeting its employees, hours after the ShinyHunters cyber extortion group claimed to be behind the incident.
“On August 22, 2026, ReliaQuest was the target of a social engineering attack,” the company said in an August 23 blog post.
“While unsuccessful beyond temporarily exposing one identity, the attempt was an important reminder of the persistent tactics of threat actor groups and what all organizations can do to guard against them.”
The ReliaQuest blog was published shortly after ShinyHunters called out the company on its darknet leak site.
“This time the post is about you, not us,” the hackers said on the same day.
“Let Mandiant report and advise on us accurately, go away.”
ShinyHunters also shared three screenshots of an Okta SSO account, including the name and details of the compromised identity.
According to ReliaQuest, the threat actor created a lookalike domain and a fake ReliaQuest single sign-on page, before calling multiple employees and posing as a teammate directing them to the fake page. One employee was caught out by the ruse, who then entered their password, giving the hackers a “brief session on our identity dashboard”.
But that was all ShinyHunters got.
“The extent of the access was view only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched,” ReliaQuest said.
“The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.”
ReliaQuest explained that its security controls include “device trust,” which prevents non-registered devices from accessing any of the company’s systems, and promptly terminated each of the attacker’s sessions before expiring the abused password.
The company followed up with a complete audit looking for any suspicious activity, confirming that the hacker had merely acquired view-only access.
“No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established,” ReliaQuest said.
“Claims that ReliaQuest was compromised or targeted by ransomware are false.”
For its part, ShinyHunters told reporters at Bleeping Computer that its access was limited.
"No additional identities were accessed, no business applications were reached, no customer or ReliaQuest data was accessed beyond the user's login credentials, and no persistence was established," a spokesperson for the group told the outlet.
When asked about ShinyHunters’ claims, a ReliaQuest spokesperson referred Cyber Daily to the company’s August 23 blog post.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.