ReliaQuest LLC Data Breach

Alleged

ShinyHunters claim involving ReliaQuest LLC

Published: Aug 23, 2026 ShinyHunters
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ReliaQuest LLC
Industry
Cybersecurity
Threat Actor
ShinyHunters
Date of Incident
Aug 23, 2026

Executive Summary

ReliaQuest, LLC, a cybersecurity technology company based in the United States, was listed as a victim on the ShinyHunters extortion group’s platform on August 23, 2026. The company provides security operations and threat detection platforms to enterprise clients. The targeting of a cybersecurity vendor by ShinyHunters is a high-signal event, demonstrating the group’s willingness to pursue organizations regardless of their security awareness or defensive capabilities, and potentially generating downstream concern for ReliaQuest’s own client base. Over the past 60 days, ShinyHunters has claimed approximately 20 victims, with Technology, Healthcare, and Professional Services as its top targeted industries. The United States, Israel, and Switzerland are the group’s most frequently affected countries. Other US technology companies listed by ShinyHunters in the current period include CyrusOne, LLC, while BOK Financial represents a concurrent high-profile US-based financial services target. ReliaQuest’s cybersecurity industry classification within the technology sector makes this one of ShinyHunters’ more notable recent listings from a reputational and downstream client impact standpoint.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for reliaquest.com in the queried slice. ShinyHunters operates primarily as a data extortion group rather than a ransomware operator. The access mechanisms the group most commonly employs—including direct database exposure, authentication bypass, and third-party data pipeline compromise—differ substantially from the infostealer-driven initial-access patterns associated with ransomware affiliates. A null stealer-log result does not meaningfully constrain the likely access pathway for a ShinyHunters listing, and infostealer-driven initial access is not considered a dominant vector for this actor class. The absence of stealer-log records for reliaquest.com does not rule out a compromise, as credentials may exist under alternate corporate domains, use personal email aliases, reside in feeds outside the queried dataset, or may have been used and rotated before indexing.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.