ReliaQuest has responded to compromise claims following a social engineering attack attributed to ShinyHunters, asserting that the threat actor did not successfully breach its systems. The company has provided details about the attack method while refuting reports suggesting a full compromise occurred.
ReliaQuest confirmed that one of its employees fell victim to a social engineering attack that provided attackers with a password and temporary access to the company's identity system. Extortion group ShinyHunters subsequently posted screenshots on its leak site, claiming responsibility and taunting the cybersecurity firm over the breach. The incident followed an earlier exchange between ShinyHunters and ReliaQuest's threat research team on social media.
ReliaQuest has confirmed that threat actor ShinyHunters exploited a phishing attack against an employee to gain access to a dashboard within the company's systems. The company claims that the scope of the breach was limited, though the specific data accessed or exposed was not detailed in the report.