"Claims that ReliaQuest was compromised or targeted by ransomware are false." — ReliaQuest
ReliaQuest’s public rebuttal and timeline
ReliaQuest published a detailed account after what it described as a social engineering incident that briefly exposed its identity dashboard. The company pushed back strongly against external assertions that it had been compromised or hit with ransomware, calling those claims “false.”
ReliaQuest said it had been investigating a new campaign by the threat group ShinyHunters, which it said was using .claims domains in social engineering attacks. An August 17 post on X from ReliaQuest drew a reply from a member of the group that included what appeared to be screenshots of ReliaQuest’s Okta dashboard and the message: “Who's hunting who?” That exchange was removed from X, and the screenshots later reappeared on a ShinyHunters-linked leak site on August 23, according to SOCRadar.
Anatomy of the social engineering attack (August 22)
According to ReliaQuest’s writeup, the active social engineering attack occurred on August 22. The threat actor registered a lookalike domain and deployed a fake ReliaQuest single sign-on (SSO) page behind a content delivery network. Attackers then phoned multiple ReliaQuest teammates, each time posing as a security employee by name and attempting to steer them to the fake SSO page.
ReliaQuest described a single successful step in the chain: one teammate entered their password and approved the push notification on their phone. That action “handed the attacker a brief session on our identity dashboard,” the company said.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat was accessed, and how ReliaQuest contained it
ReliaQuest emphasized that the session the attacker obtained was view-only. The company stated clearly that no applications, systems or customer data were accessed, despite the threat actor’s attempts.
ReliaQuest described layered controls that limited the impact. “We don’t treat a sign-in to our identity provider as permission to do anything at all,” the post said. Controls cited include device trust that prevents non-ReliaQuest devices from accessing any application or systems. Containment actions, the company added, terminated the attacker’s sessions, expired the password, and reset every authentication factor.
SOCRadar’s corroboration and the threat actor’s behavior
SOCRadar’s analysis supported ReliaQuest’s account of tactics and public posturing. It characterized the ShinyHunters’ exchanges as illustrating “the actor’s pressure tactics and public taunting,” and stated that those posts “do not substantiate the breach claim or demonstrate access to ReliaQuest networks.”
The timeline recorded in the public record shows a sequence of noisy public posts and private social engineering attempts: the August 17 X exchange with apparent Okta screenshots, the August 22 social engineering incident ReliaQuest describes, and the reappearance of screenshots on a ShinyHunters-linked leak site on August 23, per SOCRadar.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: the incident highlights the use of lookalike domains and fake SSO pages behind CDNs as effective pretexts in phone-based social engineering. ReliaQuest’s account underscores the value of device trust and of not granting broad privileges after an identity-provider sign-in.
- Affected enterprises and procurement leaders: customers and partners will note ReliaQuest’s assertion that no applications, systems or customer data were accessed, and that containment actions (session termination, password expiry, factor resets) were taken rapidly.
- End users and general workforce: ReliaQuest’s frank admission — “Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate’s name” — is a reminder that social engineering can succeed even against trained staff, and that push-approval workflows and phone-based verification have risks.
ReliaQuest’s narrative, reinforced by SOCRadar’s analysis, draws a clear line between a brief, view‑only session obtained through social engineering and a full network compromise or ransomware attack. The public taunting and screenshot postings that followed complicated the picture, but—according to the company and SOCRadar—do not change the technical assessment that no systems or customer data were accessed. Whether the campaign using .claims domains and public taunting will produce materially different outcomes in future attempts remains the immediate question.
https://www.infosecurity-magazine.com/news/reliaquest-not-compromised-by/




