Threat actor ShinyHunters claimed to have hacked cybersecurity firm ReliaQuest, with one breach-tracking report listing the incident as a ransomware-related compromise affecting the U.S.-based technology company and its reliaquest.com domain. The claim surfaced after ReliaQuest had publicly reported on ShinyHunters activity, and the threat actor’s message reportedly referenced Mandiant as part of its taunt.
A separate report said the claim remained unverified because ShinyHunters did not publish proof of compromise. It added that ReliaQuest’s threat research account had posted days earlier that it was tracking another ShinyHunters campaign, and that after a forum user replied with screenshots and the remark “Who’s hunting who?”, the related post was deleted and the account had not posted again, fueling attention around the alleged incident without confirming that a breach occurred.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Another forum user replied with screenshots and the comment "Who's hunting who?" in connection with the ShinyHunters claim involving ReliaQuest. Reporting says ReliaQuestTR then deleted its earlier August 17 tweet.
A reported ransomware-related data breach targeting ReliaQuest, LLC was attributed to ShinyHunters. The incident's breach and discovery time were both listed as 2026-08-23 02:27 UTC, though separate reporting said the actor provided no proof for its claim.
On August 22, 2026, threat actors impersonated ReliaQuest security staff, used a lookalike domain and fake SSO portal, and convinced one employee to enter credentials and approve an MFA push. ReliaQuest said the attackers gained only a temporary view-only identity-dashboard session, then had the session terminated and the account reset, with no access to internal systems or customer data.
ReliaQuest's @ReliaQuestTR account tweeted that it was tracking another ShinyHunters campaign. The post was later referenced in reporting about ShinyHunters' subsequent claim against ReliaQuest.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcehookphish.com
Open sourcereliaquest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.