ShinyHunters and ReliaQuest trade blows over claimed breach

← Back to the feed

ShinyHunters and ReliaQuest trade blows over claimed breach

The Register · 2 hours ago

The ransomware and extortion group ShinyHunters has claimed cybersecurity firm ReliaQuest as its latest victim, posting screenshots on its leak site purportedly showing access to the company's Okta identity dashboard. ReliaQuest has pushed back, confirming a social engineering attack occurred but insisting it was contained to briefly exposing a single employee's identity session, with no systems, applications or customer data compromised. The dispute follows earlier public sparring between the two, after ReliaQuest researchers highlighted ShinyHunters' use of fake company ".claims" domains in its phishing campaigns.

According to ReliaQuest's own account, attackers built a fake single sign-on page and phoned employees while posing as internal security staff; one employee entered their password and approved an MFA push, briefly handing over session access. The company says device-trust controls stopped the intruder reaching any real systems, and its security team promptly killed the session and reset the employee's credentials. No stolen data has been published, and threat intelligence firm SOCRadar found no validated samples, ransom demand or evidence of customer impact, leaving the row centred on how far the breach actually went rather than whether it happened at all.

  • ShinyHunters claims ReliaQuest breach; firm disputes scope of access
  • Attack via fake SSO page phished one employee's MFA session
  • ReliaQuest says controls blocked further access; no data leaked

Cybersecurity Technology

Read the full article at the source →