ShinyHunters and ReliaQuest are offering sharply different accounts of a claimed breach, according to The Register. The ransomware crew listed the US-based cybersecurity company on its leak site on August 23, 2026, presenting ReliaQuest as its latest victim and linking to screenshots it claimed showed access to the company’s Okta dashboard. ReliaQuest is not denying that an attack occurred. The company told The Register it was targeted on August 22, 2026, by a social-engineering operation, but said the attempt was “unsuccessful beyond temporarily exposing one identity.” ReliaQuest said the access was view-only, and that no company applications, systems, or customer data were accessed. The dispute is therefore not over whether an employee was phished. It is over what that foothold meant. ShinyHunters is framing the incident as a breach; ReliaQuest says its controls prevented the attackers from converting an exposed identity session into access to anything operationally sensitive. According to The Register’s account of ReliaQuest’s technical write-up, the attackers created a fake ReliaQuest single sign-on page and called several employees while pretending to be members of the company’s security team. One employee entered a password and approved a multifactor authentication push, giving the attacker temporary access to that employee’s identity session. ReliaQuest says the attack stopped there. The company’s device-trust controls blocked the attacker from using the session to reach ReliaQuest applications or systems, according to The Register. ReliaQuest said its security team then killed the session, expired the employee’s password, and reset the employee’s authentication factors. The Register also reported that the leak-site listing did not include stolen customer data. SOCRadar, cited by The Register, said it had found no validated data samples, ransom demand, or evidence of customer impact. There was already public tension between the two sides. Days before the listing, ReliaQuest researchers had written about ShinyHunters registering company-name “.claims” domains as part of social-engineering campaigns. The Register reports that an account associated with the crew later responded with screenshots and the question, “Who’s hunting who?” For now, the evidence described by The Register supports a narrower incident than ShinyHunters’ public framing. ReliaQuest acknowledges one phished employee identity session; ShinyHunters claims victim status. The unresolved question is whether the attackers can produce evidence beyond identity-dashboard screenshots to support a broader compromise. Who benefits: Security teams using device-trust and session-control policies have a concrete case to point to, if ReliaQuest’s account holds. ReliaQuest also benefits if no customer data or system access emerges. Who's exposed: Organizations relying heavily on push-based multifactor authentication remain exposed to impersonation calls and fake sign-on pages. ReliaQuest is reputationally exposed until the gap between ShinyHunters’ claim and the company’s denial is fully resolved.