# When ShinyHunters Comes for the Security Company
ShinyHunters didn't need a zero-day to go after ReliaQuest. They just needed a phone call — and someone with a convincing story about being on the security team.
ReliaQuest, the Tampa-based managed detection and response firm, confirmed this week that one of its employees was targeted in a social engineering attack in which threat actors posed as a member of ReliaQuest's own security staff. The attack failed. The data stayed put. But the attempt itself tells you something important about where this group is headed.
## The Attack That Almost Wasn't Newsworthy
In the normal cycle of breach news, a failed attack barely registers. No records stolen, no ransom paid, no customer notification letters going out — move on.
But this one is worth pausing on, because of who was targeting whom and how.
ShinyHunters is not some basement operation. Over the past three years, the group has racked up a staggering list of victims: Ticketmaster (560 million records), Santander Bank, AT&T, and dozens of companies whose data was exfiltrated through the Snowflake cloud storage breach in 2024. Their signature move isn't sophisticated malware or living-off-the-land exploits. It's manipulating people. They are exceptionally good at it.
Targeting a cybersecurity company is a deliberate escalation. ReliaQuest sits inside the networks of its clients — financial institutions, healthcare systems, critical infrastructure operators. Compromise the vendor, and you inherit access to everything downstream. Security companies represent the highest-yield single target in the enterprise ecosystem.
## The Impersonation Vector Is the Story
What makes this particular attempt notable is the specific vector: impersonating an internal security team member.
Think about what that requires. The attacker either researched or previously obtained enough information about ReliaQuest's staff to make the impersonation credible — names, maybe roles, possibly org chart details. This isn't cold calling. It's targeted spearphishing with a voice attached to it.
There's a brutal logic to posing as someone from the internal security team specifically. When a "security colleague" reaches out urgently — about an incident in progress, about credentials that need resetting, about a system showing anomalous behavior — the social pressure to comply is enormous. Employees are trained to trust their security team. The attack weaponizes that trust directly.
The Lapsus$ group ran similar playbooks in 2022, targeting Okta, Microsoft, and Nvidia by social engineering help desks and customer support staff. ShinyHunters appears to have refined the same technique for a higher-value target: the security operations team itself.
## What "Failed" Actually Means
ReliaQuest's statement that the attack "failed" deserves some examination. In this context, it likely means the employee didn't hand over credentials or access, the attack was detected before any data exfiltration occurred, and incident response kicked in appropriately.
That's genuinely good news. The controls worked. But the fact that the attack *reached* an employee in a convincing enough form to require a response suggests ShinyHunters had done meaningful reconnaissance on the organization. You don't impersonate a specific person on a specific team without target intelligence. That intelligence came from somewhere — LinkedIn, prior breach data, open-source research, or possibly an earlier, quieter intrusion.
The failed attack is the publicly visible part. What matters for defenders is the reconnaissance phase that made it possible in the first place.
## HackWire Analysis
ReliaQuest getting targeted by ShinyHunters isn't surprising — it's predictable. Security vendors are the logical next tier of targets for a group that has already worked through major cloud storage platforms and financial institutions. Compromise a managed security provider and you effectively get a master key to its entire client list. The economics are obvious.
What's less discussed is the specific signal this sends about ShinyHunters' operational maturity. The group started with credential stuffing and data theft from poorly secured cloud buckets. The Snowflake campaign in 2024 showed they could coordinate large-scale attacks across dozens of victims simultaneously. Now they're running precision social engineering operations against the exact companies whose job is to detect this kind of thing.
That's not a group that got lucky. That's a group that learns.
The impersonation-of-internal-security-staff vector should prompt every security organization to think hard about out-of-band verification protocols. If someone calls claiming to be from your InfoSec team and asks for something sensitive, what's the fallback verification path? Most organizations have weak answers to that question. "Call them back on their known number" sounds simple until the attacker has already spoofed caller ID or the employee assumes the known colleague is legitimately reaching out via a new line.
Mandatory secondary verification for any sensitive request — even from internal security contacts — needs to be a hard policy, not a recommendation. ReliaQuest apparently had something in place that stopped this. Most of their clients probably don't.
The broader pattern here: 2024's Snowflake campaign established ShinyHunters as a serious, organized threat actor with the patience to chain attacks across multiple victim organizations. 2025's targeting of security vendors suggests they're deliberately working their way up the trust hierarchy. The next logical step is going after identity providers, MDR platforms, and security tool vendors with access to privileged environments. If you sit in that category, you should be treating yourself as a high-value target — because ShinyHunters is.
— HackWire Editorial
## Related Coverage