ShinyHunters claims hack of ReliaQuest: taunts without proof from an extortion crew under scrutiny
On August 23, 2026, the data-theft extortion group ShinyHunters added ReliaQuest, a Tampa-based managed detection and response provider, to its Tor-hosted leak site. The group's forum post carried the taunting question "Who's hunting who?" alongside screenshots that it says show access to the security firm's systems. What the post does not include is any independently verifiable proof: no sample documents, no customer data, no details about when an intrusion might have happened or how. As of this writing the claim remains exactly that, a claim, and ReliaQuest has not confirmed any breach.
A reply to research, posted as screenshots
The timing is hard to miss. On August 17, the ReliaQuest Threat Research account tweeted that it was tracking yet another ShinyHunters campaign, part of a series of recent reports the firm has published on the group's tactics. According to DataBreaches, after a ShinyHunters-affiliated account replied on August 23 with screenshots and the "Who's hunting who?" line, the ReliaQuest Threat Research account deleted its August 17 tweet and has not posted since. Observers have read the silence in different ways: some see a sign that something real may have occurred, others note that deleting a post about an active extortion attempt is also standard incident hygiene. Neither reading amounts to confirmation. What is claimed, and what is missing
Leak-site listings are pressure tools first and evidence second. Groups routinely name victims before negotiations begin, sometimes before any meaningful exfiltration has been demonstrated, because the listing itself creates urgency for the target and anxiety among its customers. In this case the listing is thin even by those standards. Analysts tracking the claim, including SOCRadar, report no validated samples of stolen data, no confirmed customer impacts, and no regulatory or breach notifications tied to ReliaQuest. A subsequent report by CyberInsider described an incident analysis published by ReliaQuest Threat Research covering an attack attempt on August 22 that the company said was successfully blocked, though the company did not attribute the attempt to ShinyHunters or confirm that any data was taken. Until more substantial evidence surfaces, the responsible position is that a breach is alleged, not established. The PeopleSoft backdrop
The ReliaQuest claim lands in the middle of a busy stretch for ShinyHunters. In June, Mandiant and Google Threat Intelligence Group attributed an active extortion campaign against universities to the group, built on exploitation of CVE-2026-35273, an unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management component. The attacks ran between May 27 and June 9, before Oracle issued its advisory and patch on June 10, meaning the flaw functioned as a zero-day throughout. Google notified more than 100 organizations whose internet-facing systems appeared exposed, roughly 68 percent of them in higher education, mostly in the United States. The University of Nottingham publicly confirmed that a significant amount of student and alumni data was stolen. CyberScoop reported at the time that extortions were still being sent weeks into the campaign, and Mandiant's Charles Carmakal cautioned that victims beyond Google's visibility were likely affected. Vishing and the SSO problem
The PeopleSoft campaign is only one arm. ShinyHunters has simultaneously run large-scale voice-phishing operations that target the identity layer rather than the application layer. As documented in CyberScoop's coverage of the group's vishing activity, operators call employees while posing as IT help-desk staff, convince them to approve a multi-factor authentication prompt or enter credentials into a real-time reverse-proxy page, then hijack the resulting single sign-on session and harvest data from connected business applications such as CRM platforms. It is the same playbook the group applied against Salesforce customers through 2025, refined with company-specific lures and domain registrations designed to look plausible to a busy support worker. The lesson for defenders is uncomfortable but simple: a fully patched network can still be walked into if one employee trusts one phone call. Watching leak sites without believing them
For anyone who monitors these groups through their Tor-hosted shaming sites, the ReliaQuest episode is a reminder of both the value and the limits of that telemetry. Leak-site listings are genuine signals of intent and negotiation posture, which is why we track them systematically in our coverage of ransomware leak sites on onion services. They are also unverified assertions made by parties with every incentive to exaggerate. When the named victim is itself a threat-intelligence firm that has been publishing research on the group, skepticism should rise rather than fall: retaliation-by-listing is a plausible motive, and a screenshot is not a breach. Treat every entry as an allegation, wait for corroboration from the organization or credible independent reporting, and let the absence of proof remain the story until proven otherwise.