Threat intelligence firm ReliaQuest confirmed a brief, view-only security breach following a social engineering attack by the ShinyHunters group, while denying claims of ransomware or customer data theft.
Key Points
- ShinyHunters used a lookalike domain and phone-based social engineering to trick a ReliaQuest employee into providing login credentials on August 22.
- The attacker gained temporary, view-only access to an identity dashboard but failed to reach internal applications, systems, or customer data.
- ReliaQuest utilized device trust controls and session termination to immediately contain the threat and reset all authentication factors.
- SOCRadar analysis corroborated ReliaQuest’s report, noting that the threat group’s public taunts did not substantiate claims of a wider network breach.