ShinyHunters Claims ReliaQuest Breach
[Update] August 25, 2026: ReliaQuest Confirms Social Engineering Incident, Disputes Broader Breach Claim
A ShinyHunters-associated leak site listed ReliaQuest on August 23, 2026, raising questions about a potential data extortion attempt against the cybersecurity provider.
ReliaQuest has since acknowledged the incident. The company says the attack occurred on August 22, 2026, and that while an attacker briefly viewed one employee’s identity dashboard, no further systems, applications, or customer data were reached. We have not identified validated samples of stolen data, a ransom demand, or confirmed customer impact beyond the single exposed login session.
What Happened in the Alleged ReliaQuest Breach?
A listing naming ReliaQuest appeared on a ShinyHunters-associated leak site on August 23, 2026. Public tracking describes the post as an unverified ransomware or data extortion claim.
SOCRadar has also logged the allegation in its ReliaQuest–ShinyHunters breach entry, which summarizes the initial claim and will reflect any verified updates as more information becomes available.

Ransomware Group SLSH Claims Attack on ReliaQuest (SOCRadar Cyber Threat Intelligence)
ReliaQuest, a U.S.-based cybersecurity and managed detection and response provider headquartered in Tampa, Florida, delivers security operations through its GreyMatter platform. This central role in enterprise security makes any claim involving the company critical to monitor.
The leak-site listing alone did not initially prove a breach occurred, and early details lacked key facts about scope and access. Those gaps have now been partly closed by ReliaQuest’s own account of the incident (see below), though some points – such as ShinyHunters’ claim of deeper access – remain disputed.
Has ReliaQuest Confirmed the Breach Claim?
Yes, with important caveats about scope. ReliaQuest published a blog post confirming it was targeted in a social engineering attack on August 22, 2026. Reportedly, an attacker tricked an employee into approving a multi-factor authentication (MFA) push via a spoofed Okta login page, gaining view-only access to that one identity’s dashboard – with no other identities, business applications, or customer data touched, and no persistence established. ReliaQuest disputes ShinyHunters’ claim of a deeper compromise, and we have not identified customer notifications, regulatory filings, or breach notices beyond the company’s own statement.
Is There Any Evidence to Support the ReliaQuest Breach Claim?
The claim gained broader attention following X posts involving ReliaQuest Threat Research and an account operating under the handle @odysseusgroup.
On August 17, ReliaQuest Threat Research reported on a wider ShinyHunters campaign registering domains with company names under the .claims top-level domain (TLD). The report warned that ShinyHunters had expanded its social engineering tactics to impersonate legal teams, help desks, and IT staff.
The threat actor’s account replied to the thread with screenshots, asking, “Who’s hunting who ?”. A subsequent threat actor post claimed ReliaQuest Threat Research blocked the account following the exchange; the original ReliaQuest post and the threat actor’s reply were later removed from X.

The threat actor account replies to a ReliaQuest Threat Research post regarding ShinyHunters .claims domains, driving attention to the extortion claim.

A subsequent threat actor post claims ReliaQuestTR blocked the account following the exchange.
These exchanges illustrate the actor’s pressure tactics and public taunting, but they do not substantiate the breach claim or demonstrate access to ReliaQuest networks.
What Questions Remain About the Alleged ReliaQuest Breach?
With ReliaQuest’s confirmation, several of the original open questions are now resolved: an incident did occur, and the company has published a technical account of it. A few questions remain open:
- Will ShinyHunters publish any further material to substantiate claims of broader access, given ReliaQuest’s denial?
- Could any additional identities, systems, or data be implicated as the investigation continues?
- Has any regulator, law enforcement agency, insurer, or independent incident response firm reviewed and corroborated ReliaQuest’s account?
- Will ShinyHunters update, remove, or escalate the leak site listing?
Security teams should now treat this as a confirmed but limited social engineering incident, pending any further disclosures that would expand its scope.
Track Dark Web Threat Activity With SOCRadar XTI
SOCRadar Dark Web Monitoring helps security teams track brand, domain, and actor mentions across leak sites and underground channels.
This continuous monitoring enables teams to log when a listing first appears, track updates, detect republished data samples, and spot impersonation attempts early while maintaining a clear line between raw threat intelligence and confirmed breach evidence.

SOCRadar’s Dark Web Monitoring
What Should ReliaQuest Customers and Security Teams Do Next?
Customers should monitor official ReliaQuest communications and verify any incident-related messages through established account management or support channels. Avoid using contact details, links, or attachments from unsolicited breach notifications.
Security teams should focus on a measured precautionary response:
- Watch for suspicious login activity, unusual support requests, unexpected password resets, and impersonation attempts involving ReliaQuest.
- Monitor both vendor identifiers and internal domains for related phishing or social-engineering activity.
- Preserve relevant authentication, administrative, API, session, and data-export logs tied to the vendor relationship.
- Review MFA enforcement, privileged accounts, service tokens, integrations, and the types of data or telemetry connected to ReliaQuest.
- Reset passwords or tokens only when supported by credible indicators or a documented risk assessment, not the leak-site claim alone.
This article will be updated if new evidence, a ReliaQuest statement, validated samples, or other material developments emerge.

