ReliaQuest allegedly breached as ShinyHunters posts Okta dashboard
An employee account potentially was compromised.

Image by Cybernews
- ShinyHunters claims it has breached ReliaQuest, posting screenshots of what appeared to be the company’s Okta dashboard.
- ReliaQuest said a social engineering attack briefly exposed one employee’s identity dashboard session, but no systems or customer data were accessed.
- The case matters because Okta accounts can connect to many business apps, making one compromised login potentially valuable to attackers.
- The alleged attack underscores rising risks for cybersecurity firms, whose tools and customers make them high-value targets.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Okta’s access may have been used to compromise cybersecurity firm ReliaQuest, with prominent hackers claiming the company on the dark web.
ShinyHunters has named ReliaQuest, a major American cybersecurity company, as the latest victim on its leak site, posting screenshots that appear to show the company’s Okta dashboard.
Okta is widely used as an identity provider for workforce authentication. Its SSO platform is designed to let employees sign in once, then access connected services through a central dashboard.
This often includes SaaS business systems such as Microsoft 365, Google Workspace, Salesforce, Slack, and a long list of other business services, which all could be a goldmine for attackers.
Sensitive data could be exposed
Cybernews researchers have investigated the 3 screenshots provided by ShinyHunters. The screenshots appear to show a list of applications and services connected to ReliaQuest’s corporate identity infrastructure.
While the images do not appear to contain a large amount of immediately visible sensitive information, the alleged access is significant because Okta can serve as a gateway to numerous systems across an organization.
The screenshots appear to have been taken from an employee account, with URLs visible in the images indicating a connection to ReliaQuest.
ShinyHunters has not provided further details about what information it allegedly accessed or exfiltrated from the company.
“Okta is an identity management provider, which means that one compromised account would probably give access to other tools used across the company infrastructure, which could reveal a ton of sensitive information, be it employee data or financial info,” our researchers explained.
The alleged intrusion is particularly notable. ReliaQuest provides security operations technology designed to help organizations detect and respond to threats across their environments.
Its customers rely on it to monitor and manage security operations, making an alleged compromise of the company an uncomfortable example of the risks facing security providers themselves.
ReliaQuest says the social engineering attack was contained
In a post, ReliaQuest admitted that on August 22nd, the company was the target of a social engineering attack.
“The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network,” the company explained.
“The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page.” According to them, one employee entered their password and approved the push notification on their phone.
That handed the attacker a brief session on our identity dashboard,ReliaQuest stated.
They reassured that no ReliaQuest applications or systems were accessed, nor was any customer data ever touched.
“The threat actor continued with attempts to access these applications from the dashboard but was consistently denied due to the security controls in place.”
“Who is hunting who?” ReliaQuest breached after reporting on ShinyHunters
On August 17th, ReliaQuest posted on X about a broader ShinyHunters campaign that were registering bogus domains to conduct social engineering attacks.
However, the threat actors’ account replied to the thread with screenshots of Okta’s dashboard, sarcastically asking, “Who’s hunting who?”
The company later allegedly deleted its initial post and blocked the threat actor.
Attack spree to steal access
The attack may be connected to the spree of attacks conducted by ShinyHunters, which phish for Okta access to target companies worldwide. Among the latest victims is the American telehealth wellness platform Hims&Hers.
Identity providers have become attractive targets for attackers. An identity account is potentially much more valuable than a single application login, as it may grant access to multiple applications at once.
In a January blog post, Okta researchers revealed the hackers behind the sophisticated social engineering campaign are targeting employees by impersonating IT support staff.
Once hooked, unsuspecting employees are directed to fake websites and instructed to enter login credentials and multi-factor authentication (MFA) codes, effectively giving attackers free rein to move across multiple systems without triggering traditional security alarms.
As of 2026, more than 12,000 companies use Okta’s cloud-based identity and access management (IAM) platform.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Who are ShinyHunters
The primarily English-speaking extortion group has been linked to numerous high-profile breaches over recent years and has built a reputation for stealing and monetizing large datasets.
Just recently, the gang listed Logitech’s subsidiary StreamLabs. In June, the gang hit Sysco, the world’s largest food distributor, and American fashion giant Ralph Lauren.
ShinyHunters is also believed to be behind the extortion campaign targeting Oracle's PeopleSoft enterprise software and accounting giant EY.
Previously this year, the gang hit Dutch telecommunications giant Odido and the European Commission. It is also behind attacks on Cisco Systems, GTA creators Rockstar Games, and US investment advisory firms Mercer Advisors and Beacon Pointe Advisors.
And it was partly responsible for last year’s Salesforce heist, which was claimed by a conglomerate of 3 gangs, dubbed Scattered LAPSUS$ Hunters. ShinyHunters is a member of this trio.
The Salesforce attacks affected more than 700 other companies, including Cloudflare, Zscaler, Palo Alto Networks, Google, Allianz Life, TransUnion, Farmers Insurance, Air France, and KLM.