2026 ReliaQuest — ShinyHunters vishing; view-only Okta access, no customer data (confirmed)
Data compromised
Company: temporary view-only Okta identity-dashboard access for one employee session; no ReliaQuest apps, systems, or customer data accessed per investigation
Technical writeup
ReliaQuest confirmed (August 24, 2026, BleepingComputer) that ShinyHunters vishing impersonating a security employee led one staff member to enter credentials on a reliaquest.claims phishing page and approve MFA, granting temporary view-only access to the Okta identity dashboard. Device-trust controls blocked application access; the company says no ReliaQuest apps, systems, or customer data were reached, sessions were terminated, and investigation found no persistence or additional account compromise. ShinyHunters listed the firm on its leak site with Okta screenshots matching the incident. recordsAffected 0; companyConfirmed true for incident with no attested data theft.
Root cause
Social-engineering/vishing against employees via reliaquest.claims fake SSO; one employee credentialed attacker to view-only Okta dashboard (Aug 2026)
References
- https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/
- https://reliaquest.com/blog/threat-spotlight-social-engineering-attempt-against-reliaquest-what-we-found/
- https://databreaches.net/2026/08/23/shinyhunters-claims-hack-of-reliaquest-but-provides-no-proof/