ReliaQuest
| Primary URL | Location | Industry | reliaquest[.]com |
Country
United States of America
|
Technology
|
|---|
Profile
ReliaQuest experienced a social engineering attack on August 22, 2026. The threat group behind the incident was identified as ShinyHunters. The attackers utilized a lookalike domain to masquerade as a legitimate service. In conjunction with the domain, they fabricated a counterfeit single sign‑on page. The fake page was designed to capture credentials from unsuspecting users.
An employee of ReliaQuest was deceived by the counterfeit SSO page. The employee inadvertently granted brief view‑only access to the attacker. This access was directed toward ReliaQuest’s identity dashboard. No internal systems were accessed or altered during the episode. No customer data was exfiltrated or otherwise compromised.
The incident was reported by Infosecurity Magazine in an online article. The article can be accessed at https://www.infosecurity-magazine.com/news/reliaquest-not-compromised-by. The report emphasized that the breach did not lead to any compromise of ReliaQuest’s environment. The granted access was strictly limited to viewing privileges, with no ability to modify data. The episode illustrates how lookalike domains can be leveraged in social engineering campaigns. It also demonstrates the effectiveness of counterfeit SSO pages in credential harvesting attempts. ReliaQuest’s identity dashboard was the specific asset targeted for the view‑only access.