Urgent.News

What's breaking now, across thousands of outlets.

Tech

ShinyHunters and ReliaQuest trade blows over claimed breach

Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got

ShinyHunters and ReliaQuest trade blows over claimed breach

Cybersecurity firm ShinyHunters has claimed that it compromised the systems of information security business ReliaQuest. However, ReliaQuest maintains that the social engineering attack only succeeded in exposing a single employee's identity before its defenses blocked further access. The ransomware group posted screenshots on August 23 showing access to ReliaQuest's Okta dashboard, but did not release any stolen customer data or ransom demands.

ReliaQuest's spokesperson confirmed that an attack took place on August 22, but disputed ShinyHunters' claim of full system compromise. The attackers set up a fake single sign-on page and impersonated the company's security team, leading one employee to approve multi-factor authentication and provide temporary access. ReliaQuest's controls prevented the attacker from accessing any company applications or systems, and the situation was resolved within hours.

ShinyHunters responded by accusing ReliaQuest of inaccurate reporting and demanding a more truthful account. While both sides agree that an employee was successfully phished, they disagree on whether the breach resulted in any meaningful system access.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Monday 24 August →