ReliaQuest, a Tampa, Florida-based cybersecurity technology company, has reportedly been named by a cybercriminal group in connection with a data security incident. According to a posting identified on a dark web leak site, the ShinyHunters extortion group claimed responsibility for obtaining data tied to ReliaQuest’s employees and third parties.
Companies that provide cybersecurity, IT, and managed security services handle enormous volumes of sensitive client and employee data, and they carry a heightened responsibility to protect that information given the trust their own customers place in them.
ReliaQuest’s Data Breach Investigation
Data breach lawyers are investigating a cybersecurity incident reportedly involving ReliaQuest, a Tampa-based company that provides security operations and threat detection services to enterprise clients around the world. The investigation began after a posting appeared on a dark web leak site in which the extortion group ShinyHunters claimed to have obtained data connected to ReliaQuest. As of this writing, ReliaQuest has not publicly confirmed that a breach occurred, and the full scope of what may have been accessed remains unclear.
According to the reported posting, the claim involved credentials tied to both employees and third parties associated with ReliaQuest. The specific categories of personal information potentially exposed have not been confirmed publicly. Investigators are working to determine exactly what data, if any, was accessed and how many individuals may be affected.
ShinyHunters is a known data extortion group that has claimed credit for a series of high-profile incidents in 2026, targeting technology, healthcare, and professional services companies across the United States and abroad. Rather than deploying ransomware to encrypt a victim’s systems, groups like ShinyHunters typically focus on stealing data and then pressuring the victim company by threatening to publish or sell the stolen information. The targeting of a cybersecurity vendor is notable because these companies are themselves entrusted with protecting other organizations’ networks and data, meaning a successful attack can raise concerns that ripple outward to a company’s own client base.
Cybersecurity and technology companies are frequent targets for this type of extortion attempt precisely because they store credentials, access keys, and sensitive operational data not just for themselves but often on behalf of the clients they serve. When employee or third-party credentials are compromised, the risk extends beyond the immediate company. Stolen login information can potentially be reused to gain access to connected systems, email accounts, or other services if individuals have reused passwords across multiple platforms.
Regardless of a company’s size or its own area of expertise, any organization that collects and stores personal information is expected to maintain reasonable administrative, technical, and physical safeguards to protect that data from unauthorized access. When those safeguards fail, or when a company does not respond quickly and transparently once a potential compromise is discovered, the individuals whose information was placed at risk may have legal recourse.
Notification laws vary from state to state, but most require companies to investigate a suspected breach, determine which individuals were affected, and notify them within a defined window once the scope of the incident is understood. Because ReliaQuest has not yet confirmed the incident publicly, it is not yet clear whether or when formal notification letters might be sent to affected individuals, or what specific information those notices might disclose.
Data breach investigations like this one often take weeks or months to fully resolve, particularly when the initial evidence comes from a dark web posting rather than an internal discovery by the company itself. Forensic investigators typically need to confirm whether the claimed access is genuine, identify which systems or accounts were involved, and cross-reference any data samples released by the threat actor against the company’s own records before a full accounting can be provided to the public or to regulators.
Compromised employee or third-party credentials at a technology vendor can be especially valuable to a group like ShinyHunters, since login information reused across multiple platforms may allow further unauthorized access well beyond the original point of entry. This is one reason security researchers generally recommend unique passwords for every account and encourage prompt password resets any time a service a person uses has been named in connection with a possible incident, even before every detail of that incident has been confirmed.
In the meantime, individuals who have done business with ReliaQuest, or whose employer or vendor relationships intersect with the company’s platforms, are encouraged to stay alert for any official communication and to take precautionary steps to protect their personal information, discussed further below.
When Did This Breach Occur?
According to the dark web posting reviewed by investigators, the claimed incident was dated to on or around August 23, 2026, when ShinyHunters listed ReliaQuest on its leak site. ReliaQuest has not issued a public statement confirming an exact incident date, detection date, or notification timeline. It is common for the date a threat actor posts a claim to differ from the actual date unauthorized access first occurred, since many intrusions go undetected for a period of time before they are discovered or publicly disclosed. As this investigation continues, updates about the confirmed timeline, including when ReliaQuest first became aware of any unauthorized activity and when, if ever, affected individuals are formally notified, will be added here.
What Information Was Breached?
The specific categories of personal information potentially exposed in this incident have not been publicly confirmed. The dark web posting reviewed by investigators referenced credentials belonging to employees and third parties associated with ReliaQuest, but did not provide a complete or verified list of data types. Depending on the nature of the systems involved, data breaches at technology and cybersecurity companies can potentially expose information such as names, email addresses, and account login credentials. Until ReliaQuest or an official notification confirms the exact data types involved, individuals should treat any account or credential associated with the company as potentially at risk and take the precautionary steps outlined below.
What You Can Do
If you believe your information may have been exposed in the ReliaQuest cybersecurity incident, there are several steps you can take to help protect yourself, including:
- Monitor your financial accounts, email accounts, and any accounts associated with ReliaQuest for signs of unauthorized activity
- Change your password on any account that may share credentials with ReliaQuest, and avoid reusing passwords across multiple sites
- Enable two-factor authentication wherever it is available
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Be cautious of phishing emails, texts, or phone calls referencing this incident or asking you to verify personal information
- Keep any notification letter or communication you receive about this incident for your records
File a Data Breach Lawsuit Against ReliaQuest
If you were affected by the ReliaQuest cybersecurity incident, you may be entitled to compensation. Companies that collect and store personal information have a legal responsibility to protect it, and when that responsibility is not met, affected individuals may be able to pursue a data breach class action lawsuit to recover damages related to identity theft, financial losses, and the time and expense of protecting themselves going forward.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.