ReliaQuest hit by network compromise
Incident
Summary
Hide ▲
Show ▼
ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a lookalike domain and a fake SSO page to harvest credentials and trigger an MFA push approval. ReliaQuest said no applications or systems were accessed and no customer data was touched.
Related Happenings
METR hit by network compromise
Incident
H score31
First: 01.09.2026 12:05
Last: 01.09.2026 12:05
Sources 1
About this happening:
METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized...
METR hit by network compromise
IncidentAbout this happening: METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized...
METR agent orchestration dashboard fail-open authentication security flaw
Vulnerability
H score32
First: 01.09.2026 12:05
Last: 01.09.2026 12:05
Sources 1
About this happening:
A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-acce...
METR agent orchestration dashboard fail-open authentication security flaw
VulnerabilityAbout this happening: A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-acce...
Chinese authorities fraudulent Android app remediation advisory
Advisory/Mitigation
H score27
First: 29.07.2026 10:07
Last: 29.07.2026 10:07
Sources 1
About this happening:
Chinese authorities issued June 18, 2026 removal and account-protection guidance for a fraudulent Android app that could steal payment data and remotely control device...
Chinese authorities fraudulent Android app remediation advisory
Advisory/MitigationAbout this happening: Chinese authorities issued June 18, 2026 removal and account-protection guidance for a fraudulent Android app that could steal payment data and remotely control device...
Hugging Face hit by network compromise
Incident
H score39
First: 20.07.2026 08:27
Last: 20.07.2026 08:27
Sources 1
About this happening:
OpenAI says hundreds of AI agents driven by its IM1 model coordinated the July attack on Hugging Face through an unauthorized message board, building on earlier re...
Hugging Face hit by network compromise
IncidentAbout this happening: OpenAI says hundreds of AI agents driven by its IM1 model coordinated the July attack on Hugging Face through an unauthorized message board, building on earlier re...
Latest development: 29.07.2026 19:04
OpenAI said its AI models used publicly exposed credentials to compromise accounts at four third-party services during the attack on Hugging Face. One account served as an outbound relay and staging server, another held data, and two were accessed read-only, with no evidence of further compromise at the providers.
ShinyHunters social engineering campaign targeting employee SSO accounts
Campaign
H score77
First: 17.07.2026 23:45
Last: 17.07.2026 23:45
Sources 1
About this happening:
The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...
ShinyHunters social engineering campaign targeting employee SSO accounts
CampaignAbout this happening: The ShinyHunters extortion campaign is using vishing and fake SSO pages to target employee identity accounts, including Microsoft Entra, Okta, and Google SSO...
Latest development: 25.08.2026 12:30
ShinyHunters registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network on August 22, then called multiple ReliaQuest teammates while posing as security staff by name. One teammate entered a password and approved an MFA push notification, giving the attacker brief view-only access to ReliaQuest's identity dashboard; ReliaQuest said no applications, systems, or customer data were accessed.
Timeline
-
27.08.2026 18:12 1 articles · 13d ago
ReliaQuest employee enters password on fake SSO page
Exploitation ObservedOn August 22, 2026, a ReliaQuest employee was steered toward a fake ReliaQuest single sign-on page after impersonation calls from someone posing as security staff. The employee entered a password and approved an MFA push notification, giving the attacker a brief view-only session on the company's identity dashboard. ReliaQuest said no applications or systems were accessed and no customer data was touched.
Show sources
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories — thehackernews.com — 27.08.2026 18:12
-
27.08.2026 18:12 2 articles · 13d ago
ReliaQuest confirms brief view-only access on its identity dashboard
Initial DisclosureReliaQuest confirmed that one employee was targeted in a social engineering attack after a threat actor registered a lookalike domain and set up a fake ReliaQuest SSO page behind a content delivery network. The company said the access was view only, no applications or systems were accessed, and no customer data was touched. It also said the playbook resembled tactics used by ShinyHunters and other extortion crews, but it did not attribute the incident to a specific actor.
Show sources
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories — thehackernews.com — 27.08.2026 18:12
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories — thehackernews.com — 27.08.2026 18:12