INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Breach ReliaQuest

| 2026-09-03 19:42 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A breach of ReliaQuest's Okta portal by a threat actor associated with ShinyHunters was reported, but the incident appears to be more of a social engineering attempt than a full-scale breach. On September 3, 2026, an employee at ReliaQuest entered their credentials into a fake single sign-on (SSO) page, allowing the attacker to gain view-only access to the SSO portal and thwart attempts to access applications or move laterally. The incident was publicly boasted about by ShinyHunters, but it is unclear if they actually breached ReliaQuest's systems. Two alleged members of TeamPCP gang were identified and arrested in Western Australia on September 3, 2026.
Technical Mitigations AI-generated
• Use multi-factor authentication for single sign-on (SSO) portals to prevent attackers from gaining access. • Implement zero-trust security policies to limit lateral movement and restrict access to sensitive areas of the network after a breach occurs. • Regularly monitor Okta accounts for suspicious activity, such as spoofed company domains or unauthorized login attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHuntersTeamPCPTeamPCP Shai-HuludShai-Hulud
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DPRK DPRK
Incident Timeline
‎2026/09/03
A threat actor associated with ShinyHunters posted on social media platform X, saying "Who's hunting who?" and containing a photo of an Okta portal.
threat_actor ShinyHunters
threat_actor TeamPCP
Intelligence Sources
Dark Reading 2026-09-03