INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Breach ReliaQuest
| 2026-09-03 19:42 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A breach of ReliaQuest's Okta portal by a threat actor associated with ShinyHunters was reported, but the incident appears to be more of a social engineering attempt than a full-scale breach. On September 3, 2026, an employee at ReliaQuest entered their credentials into a fake single sign-on (SSO) page, allowing the attacker to gain view-only access to the SSO portal and thwart attempts to access applications or move laterally. The incident was publicly boasted about by ShinyHunters, but it is unclear if they actually breached ReliaQuest's systems. Two alleged members of TeamPCP gang were identified and arrested in Western Australia on September 3, 2026.
Technical Mitigations AI-generated
• Use multi-factor authentication for single sign-on (SSO) portals to prevent attackers from gaining access.
• Implement zero-trust security policies to limit lateral movement and restrict access to sensitive areas of the network after a breach occurs.
• Regularly monitor Okta accounts for suspicious activity, such as spoofed company domains or unauthorized login attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHuntersTeamPCPTeamPCP
Shai-HuludShai-Hulud
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
DPRK
DPRK
Incident Timeline
2026/09/03
A threat actor associated with ShinyHunters posted on social media platform X, saying "Who's hunting who?" and containing a photo of an Okta portal.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Last week, the cybersecurity vendor warned of a "widespread ShinyHunters campaign" using spoofed company domains in a now-deleted post on social media platform X. A account associated with ShinyHunters replied with a post that said "Who's hunting w…
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?.
ShinyHunters publicly boasted about breaching ReliaQuest, but the claims appear to be mostly hot air.
In this episode of "What We Missed," Dark Reading's
Rob Wright
and
Alex Culafi
discuss some of the recent news events and topics that didn't make it into the publication, starting with
ShinyHunters
' taunting of ReliaQuest.
threat_actor
TeamPCP
…ase
Also discussed on this episode: New research from Palo Alto Networks' Unit 42 indicates that AI-generated malware isn't a prevalent threat — at least, not yet; and two alleged members of the infamous
TeamPCP gang
were identified and arrested.
Was it TeamPCP?
Is TeamPCP even a thing?
Intelligence Sources
Dark Reading
2026-09-03
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:57
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
ReliaQuest
entity
6x
target region
Target Country
United States
country
6x
timeline
Temporal Reference
2026
date
4x
tactic
Cyber Operation Type
Data Leak
tactic
2x
industry
Targeted Sector
Media
sector
2x
threat actor
APT Group
ShinyHunters
actor
Contextual Telemetry
Context Block
8 METRICS
source region
Origin Country
Australia
country
target region
Target Region
DPRK
region
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
general metric
Unit
42
unit
general metric
Samples
12
samples
general metric
%
97
%
malware
Malware Payload
Shai-Hulud
tool
general metric
Malware Samples
405
malware samples
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.