INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Breach Exposes ReliaQuest to Failed Data-Theft Attack

| 2026-08-24 15:17 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A social engineering attack was launched against ReliaQuest on August 24, 2026, targeting one of its employees. The attackers impersonated a security team member and tricked the employee into accessing a fake single sign-on page behind a content delivery network. This led to temporary view-only access to the employee's identity dashboard, but subsequent attempts were blocked by device-trust controls. No customer data was accessed or systems were compromised beyond the user's login credentials. The attackers did not establish persistence on ReliaQuest's systems and no other accounts, apps, or data were accessed.
Technical Mitigations AI-generated
• Use a domain verification technique to detect phishing attempts, such as verifying the domain of a login page before entering credentials. • Implement device-trust controls that block subsequent attempts to access applications through an identity dashboard after initial successful authentication. • Regularly audit control fidelity and on-network access for suspicious activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

re•••••.claims
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/08/24
Threat actors used a phishing page hosted on the "lookalike domain" reliaquest.claims to target a real security employee, impersonating one of ReliaQuest's employees.
threat_actor ShinyHunters
Intelligence Sources