
ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew's social engineering attack only got as far as one employee identity before its defenses slammed the door. The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site on August 23, claiming the corporation as its latest victim. The listing, seen by The Register, links to screenshots the gang claims show access to ReliaQuest's Okta dashboard. It did not publish any stolen customer data, however, and SOCRadar said it had found no validated data samples, ransom demand, or evidence of customer impact. There had already been some public needle between the two sides. Days earlier, ReliaQuest researchers posted about ShinyHunters registering company-name .claims" domains as part of its social engineering campaigns. An account associated with the crew responded with screenshots and the question: "Who's hunting who?" ReliaQuest has now responded to the crew's claim, confirming an attack took place on August 22 but disputing the suggestion that ShinyHunters compromised its systems. "On August 22, 2026, ReliaQuest was the target of a social engineering attack. It was unsuccessful beyond temporarily exposing one identity," a ReliaQuest spokesperson told The Register. "The extent of the access was view only. No ReliaQuest applications or systems were accessed, and no customer data was ever touched." The company said it would make no further comment beyond the statement and a technical account of the incident published on its website. According to that account, the attackers set up a fake ReliaQuest single sign-on page and called several employees while pretending to be members of the company's security team. One employee entered their password and approved an MFA push, giving the attacker temporary access to their identity session. ReliaQuest says that was as far as ShinyHunters got. Device-trust controls prevented the attacker from using the session to reach company applications or systems, while the security team killed the session, expired the employee's password, and reset their authentication factors. ShinyHunters, unsurprisingly, has a different take. "This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away," reads a post on the gang's leak site, For all the posturing, the two sides aren't actually arguing over whether ShinyHunters got a foot in the door. ReliaQuest acknowledges that an employee was successfully phished and an identity session briefly exposed. The fight is over what happened next: ShinyHunters is presenting ReliaQuest as its latest victim, while ReliaQuest says its controls stopped the attacker before they could turn that foothold into access to anything that mattered. (R)