ShinyHunters Claimed It Broke Into ReliaQuest. The Reality Is More Complicated.
A cybersecurity company's own employee fell for a fake login page, handing criminals limited access. What happened next is actually a story about defences holding.

Key points
- ShinyHunters, a criminal hacking group, claimed it broke into cybersecurity firm ReliaQuest and posted screenshots as proof.
- A ReliaQuest employee was tricked into entering their login credentials on a fake sign-in page, giving criminals read-only access to one portal.
- ReliaQuest says every attempt by the criminals to access sensitive systems or move deeper into its network was blocked.
- Palo Alto Networks' Unit 42 research team found that 97% of AI-written malware samples they analysed never appeared in real-world attacks.
- Two alleged members of the cybercriminal gang TeamPCP were identified and arrested.
A hacking group called ShinyHunters spent last week taunting a cybersecurity company on social media. The company, ReliaQuest, had warned the public about a ShinyHunters phishing campaign, where criminals send fake messages to trick staff into handing over passwords. ShinyHunters replied on X (formerly Twitter) with the message "Who's hunting who?" and attached screenshots appearing to show access to a ReliaQuest employee's Okta account (Okta is a widely used login management service that lets staff sign into many work tools with one password).
So did the criminals actually break in?
What actually happened inside ReliaQuest?
Yes and no. An employee was vished, meaning tricked over the phone or by a fake website, into typing their login details into a fraudulent single sign-on page. A single sign-on, or SSO, page is one master login that opens many internal systems at once, making it a valuable target.
The credentials worked. ShinyHunters got in. But what they got into was a stripped-down view of one portal, with read-only access and nothing sensitive within reach. ReliaQuest says every attempt to open other applications or move sideways through its network was stopped cold.
The security principle that explains this is called zero trust: the idea that getting past the front door should not automatically open every other door inside the building. The criminals had a key, and it opened almost nothing.
ShinyHunters has a track record of low-impact break-ins paired with loud public boasting, a pattern borrowed from an earlier group called Lapsus$, which made headlines around 2022 by grabbing screenshots inside company portals and declaring victory. This looks like the same playbook.
ReliaQuest published a detailed account of what happened, which is worth reading on its own terms. The firm freely admits phishing works and says it expects employees to occasionally fall for attacks. What it built were the controls that limited the damage once that happened.
Did AI-written malware cause any of this?
No. But separately, Palo Alto Networks' research division Unit 42 published findings this week that are worth pausing on. The team analysed 405 malware samples, meaning malicious software written with help from AI tools, to see how dangerous they were in practice.
| Finding | Figure |
|---|---|
| Total AI-linked malware samples analysed | 405 |
| Samples seen on real, protected devices | 12 |
| Samples that appeared only in test environments | 97% |
| Real-world samples blocked by existing tools | 12 of 12 |
Every sample that reached a real device was caught by security software already in place. Unit 42 noted that most of the AI-written code looked like experiments rather than finished weapons. The takeaway is cautious: AI is making it faster to write malicious software, but the defences that mature organisations already run are still stopping it. That could change as AI models improve, but for now the threat is smaller than the headlines suggest.
Should ordinary people worry?
If you use a service protected by ReliaQuest, there is no indication that customer data was reached. The criminals got a narrow, read-only look at one internal tool and were then locked out.
The broader lesson applies everywhere. If you receive an unexpected call or message asking you to log in urgently, stop. Contact the company or your IT team directly using a number you already trust. Criminals rely on the few seconds of panic before you think it through.
First reported by Dark Reading, the ReliaQuest incident is a reminder that a breach headline and an actual breach can be very different things. Context matters.



