ReliaQuest

ReliaQuest

Cloud-native security operations platform with AI

Overview

ReliaQuest provides a security operations platform called GreyMatter for large enterprises. GreyMatter collects signals from many security tools in the cloud and uses AI and automation to detect threats and automate responses, all shown in a single view of the security posture. Its differentiators are its enterprise focus, cloud-native architecture, and its emphasis on unifying visibility across diverse tools, aided by acquisitions like Digital Shadows and EclecticIQ. Its goal is to help organizations manage security operations more effectively, improve threat detection and response, and reduce risk in complex environments.

About ReliaQuest

Simplify's Rating
Why ReliaQuest is rated
B
Rated B on Competitive Edge
Rated B on Growth Potential
Rated B on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

AI & Machine Learning

Company Size

1,001-5,000

Company Stage

Late Stage VC

Total Funding

$1.1B

Headquarters

Tampa, Florida

Founded

2007

Get referred to ReliaQuest

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • ReliaQuest passed $400 million recurring revenue and is marching toward an IPO.
  • The May 2026 Anthropic Compliance API integration expands GreyMatter into enterprise AI governance.
  • The June 2026 USF investment strengthens hiring pipelines and brand trust in Tampa.

What critics are saying

  • ShinyHunters publicly named ReliaQuest on August 23 2026, creating reputational damage risk.
  • The August 22 2026 vishing incident exposed one identity session, proving human-factor weakness.
  • Crowded MDR and SIEM-replacement markets let CrowdStrike, Splunk, and SentinelOne compress margins.

What makes ReliaQuest unique

  • GreyMatter SIEM-Less, launched July 28 2026, targets SIEM replacement economics.
  • GreyMatter integrates with 250-plus security technologies, unifying identity, endpoint, cloud, network, email.
  • Brian Murphy says GreyMatter resolved 81 million investigations across 1,500 customers.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$1.1B

Above

Industry Average

Funded Over

4 Rounds

Late VC funding comparison data is currently unavailable. We're working to provide this information soon!
Late VC Funding Comparison
Coming Soon

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

0%
CNBC
Aug 25th, 2026
ReliaQuest's AI platform resolves 81M cyber investigations, eyes IPO at $400M revenue

ReliaQuest CEO Brian Murphy revealed that the Tampa-based cybersecurity firm's agentic-AI security platform, GreyMatter, autonomously resolved 81 million investigations across 1,500 customers in the past year. The company, which was bootstrapped for nine years, has surpassed $400 million in recurring revenue. Murphy told Jon Fortt that ReliaQuest is "marching toward" an initial public offering but won't rush to time the market. The CEO, who was raised in small-town Florida, is a Florida State graduate.

DanSec
Aug 25th, 2026
Cybersecurity brief - 2026-08-25.

Cybersecurity brief - 2026-08-25. 2026-08-25 Major Incidents or Breaches * Iran-linked hackers were responsible for shutting down a UK power plant for four days, causing significant operational disruption and raising concerns about the resilience of the UK's distributed energy infrastructure [[35]]. * Apollo Global, a private equity firm, experienced a data breach that exposed personal information as part of a campaign targeting major financial companies [[33]]. * ReliaQuest confirmed that an employee was targeted in a phishing attack following the ShinyHunters breach. Attackers gained access to a dashboard, but the impact was limited and no data theft occurred [[15]] [[28]]. * A breach at South Korea's government-backed startup platform exposed encrypted personal data due to an encryption key being included in an API, highlighting key management failures [[17]]. Newly Discovered Vulnerabilities * A maximum-severity vulnerability (CVE-2026-21962) in Oracle HTTP Server and Oracle WebLogic Server is being actively exploited, allowing unauthenticated attackers to access critical data. CISA has added the flaw to its Known Exploited Vulnerabilities catalog [[3]] [[27]]. * The Zimbra Collaboration Suite is affected by an actively exploited vulnerability (CVE-2026-73570) that allows full takeover of user communications. CISA has mandated a three-day patch deadline for US government agencies [[19]] [[21]]. * Red Hat and the Keycloak project patched a critical password reset flaw that could allow unauthenticated remote attackers to take over any account on the open-source identity and access management server [[8]]. * Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress are being targeted by attackers, enabling the forging of SAML responses and unauthorized admin access [[13]]. * An unpatched flaw in Calix GS7 XGS (GS5239XG) residential routers allows remote attackers to bypass NAT and expose internal devices by creating port-forwarding rules [[12]]. * The Spring Application Framework has received patches for 91 vulnerabilities, with more than 200 vulnerabilities patched so far this year, compared to 16 in 2025 and 22 in 2024 [[31]]. Notable Threat Actor Activity * The Chinese-speaking cybercrime group UAT-10147 is targeting Windows and Linux web servers globally across education, media, technology, and government sectors. The group uses AI to scale attacks, deploys SPECTRE malware with EDR bypass, and leverages a Linux rootkit [[11]]. * Operation QUICSILVER is a cyber espionage campaign targeting Myanmar government and IT sectors using graduation ceremony invitation lures to deliver a Go-based backdoor called QUICAgent [[9]]. * Threat actors are distributing the Weedhack malware to gamers by disguising it as fake Minecraft clients and leveraging SEO poisoning [[5]]. * Multiple campaigns are using new malware families, including WordlistLoader and SynkLoader, to deliver infostealers and steal Windows credentials. These tools are being used to sell access to ransomware groups and employ techniques such as screen hijacking [[7]] [[22]] [[23]]. Trends, Tools, or Tactics of Interest * AI chatbots have been shown to be more effective than human scammers at building trust in social engineering attacks, particularly in romance scam scenarios [[1]]. * AI-enabled social engineering is increasing the effectiveness of attacks, accounting for over 85 percent of cyber insurance losses in the first half of the year [[2]]. * The rapid adoption of AI coding tools is increasing remediation debt as more code is shipped than can be effectively secured [[4]]. * Only a small percentage of AI users present disproportionate security risks, particularly those using advanced AI tools for custom development and automation [[10]]. * AI is accelerating vulnerability discovery, outpacing the rate of remediation, and tightening the window between disclosure and exploitation [[25]] [[34]]. * Malware campaigns are leveraging trending topics and fake software downloads, such as fake GTA 6 demo sites, to distribute infostealers targeting browser-stored credentials [[39]]. * Fake Microsoft security scans are being used to trick victims into uninstalling antivirus software, facilitating refund scams [[40]]. * The latest version of the ToxicPanda Android banking trojan has expanded capabilities to seize control of infected devices, block access to Google Play, and threaten enterprise environments [[24]] [[43]]. * AliExpress was found using silent audio processing as a browser fingerprinting technique, bypassing traditional cookie-based tracking [[42]]. Regulatory or Policy Developments Affecting the Security Industry * TikTok, ByteDance, and affiliates reached a $400 million settlement with the US Department of Justice over alleged violations of the Children's Online Privacy Protection Act (COPPA) [[14]] [[36]]. * The Dutch Data Protection Authority fined Uber nearly $1 billion for violations of the EU's General Data Protection Regulation related to automated suspensions of driver accounts [[30]]. * Microsoft Teams introduced a policy allowing administrators to block all identified external bots from joining meetings, enhancing meeting security [[16]]. [[1]]: Report: AI Chatbots Are More Effective at Building Trust Than Human Scammers [[2]]: Human Error Remains at the Core of AI-Enabled Social Engineering [[3]]: Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data [[4]]: Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt [[5]]: Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning [[7]]: WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords [[8]]: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account [[9]]: Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor [[10]]: The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk [[11]]: UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit [[12]]: Unpatched Calix flaw lets hackers bypass NAT to expose internal devices [[13]]: Hackers target WordPress sites in miniOrange auth bypass attacks [[14]]: TikTok reaches $400M settlement with US over COPPA violations [[15]]: ReliaQuest confirms failed data-theft attack after ShinyHunters breach [[16]]: Microsoft Teams now lets admins block external bots from meetings [[17]]: South Korean startup platform breach exposes key management failures [[19]]: CISA orders urgent patching of actively exploited Zimbra flaw [[21]]: Exploited Zimbra Flaw Highlights Shrinking Window to Patch [[22]]: Foul Language: WordlistLoader Disguises Malware as Ordinary Text [[23]]: Tricky 'SynkLoader' Multitool May Herald Ransomware [[24]]: ToxicPanda Banking Trojan Matures Into Enterprise Threat [[25]]: The Vulnerability Gap: Why Discovery Is Outrunning Repair [[27]]: CISA Warns of Exploited Oracle WebLogic Vulnerability [[28]]: ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited [[30]]: Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts [[31]]: 91 Vulnerabilities Patched in Spring Application Framework [[33]]: Personal Information Exposed in Apollo Global Data Breach [[34]]: Rethinking Application Security for the AI Era [[35]]: Iran-Linked Hackers Shut Down UK Power Plant for Four Days [[36]]: TikTok Reaches $400 Million Settlement With US Justice Department Over Children's Privacy [[39]]: Fake GTA 6 Extended Look and demo sites deliver an infostealer [[40]]: Fake Microsoft security scans trick victims into uninstalling their antivirus [[42]]: AliExpress caught using silent audio to fingerprint visitors' browsers [[43]]: ToxicPanda 2.0 can take over your Android phone and banking apps

GBHackers
Aug 24th, 2026
Hackers impersonate security staff to steal credentials in ReliaQuest social engineering attack.

Hackers impersonate security staff to steal credentials in ReliaQuest social engineering attack. August 24, 2026 ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and successfully persuaded one employee to approve a malicious multi-factor authentication (MFA) request. Data breach prevention Discover more Endpoint security software The incident, detected on August 22, 2026, resulted in the temporary exposure of a single identity session with view-only access to ReliaQuest's identity dashboard. Fortunately, the company stated that its security controls prevented the attackers from accessing business applications, customer environments, or internal systems. ReliaQuest shares threat research materials through its Resource Center and blog channels. ReliaQuest social engineering attack. According to ReliaQuest, the campaign began with the registration of a deceptive domain that closely resembled the company's legitimate web infrastructure. The attackers set up a counterfeit ReliaQuest single sign-on (SSO) portal using a content delivery network (CDN). This technique makes phishing infrastructure more resilient and less suspicious. The threat actors then conducted phone-based social engineering, known as vishing, targeting multiple employees. During the calls, the attackers impersonated named members of ReliaQuest's security staff and directed employees to authenticate via a fraudulent SSO page. One employee entered their password into the fake portal and approved a malicious MFA push notification sent to their mobile device, granting the attackers a short-lived session within the organization's identity management environment. Discover more Data privacy consulting Information security training ReliaQuest stated that the compromised session had only view-only access to its identity dashboard. Although the attackers attempted to use this access to reach additional applications, they were blocked by the company's security controls. Data breach prevention The company credited its defense-in-depth model, which includes device-trust controls that prevent unmanaged or non-corporate devices from accessing enterprise applications and systems, for containing the incident. Incident-response actions terminated the malicious session, expired the affected password, and reset all authentication factors linked to the identity. A subsequent investigation reviewed device-trust enforcement, on-network access, identity logs, control effectiveness, and any suspicious activity from the preceding 48 hours. ReliaQuest reported no evidence of additional compromised identities, no established persistence mechanisms, and no access to customer or company data beyond the exposed login credentials. The company also denied claims that it experienced a ransomware incident or a broader compromise. This attack illustrates a common identity-focused intrusion pattern that includes quickly registering lookalike domains, delivering phishing content via CDN-backed infrastructure, impersonating employees, harvesting passwords, approving MFA prompts, and attempting to enroll a new authenticator. Discover more Crime & Justice Critical vulnerability alerts Cybersecurity consulting MFA alone does not prevent attacks when users can be manipulated into approving prompts. Organizations should pair MFA with phishing-resistant authentication methods, such as FIDO2 security keys or passkeys, enforce device posture checks, restrict authenticator enrollment, and continuously monitor identity provider sessions for anomalous activity. Security teams should also treat unexpected calls from IT or security personnel as verification events. Employees should independently confirm requests through trusted internal channels rather than following a caller's instructions or navigating to a provided login page. Data breach prevention Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. Hot this week

Rankiteo
Aug 23rd, 2026
ReliaQuest: how ReliaQuest stopped a ShinyHunters breach attempt.

ReliaQuest: how ReliaQuest stopped a ShinyHunters breach attempt. ReliaQuest Thwarts ShinyHunters Social Engineering Attack Targeting Okta SSO On 23 August 2026, cybersecurity firm ReliaQuest confirmed a social engineering attack linked to the ShinyHunters threat group, which attempted to breach its systems using a fake Okta Single Sign-On (SSO) page. The attackers, posing as IT support, tricked an employee into approving a multi-factor authentication (MFA) push during an impersonation call, granting them access to a view-only identity dashboard session. The breach was contained quickly due to ReliaQuest's layered security controls, including device-trust policies that restricted the attacker to a single session. No business applications, customer data, or company data were accessed, and no persistence was established. The compromised credentials were immediately expired and reset upon detection. The attack followed a well-documented playbook: threat actors registered a lookalike domain, hosted a fake SSO page behind a content delivery network (CDN), and used phone-based impersonation to deceive the employee. The incident mirrored a recently disclosed WordPress plugin flaw that allowed authentication bypass, reinforcing the need for defense-in-depth strategies rather than reliance on single security measures. ReliaQuest's GreyMatter platform, which integrates with Splunk, CrowdStrike, Fortinet, and Google Cloud Chronicle, played a key role in normalizing telemetry data and enabling rapid response. The company emphasized that phishing remains effective, particularly when attackers leverage employee names and urgency to manipulate victims. A week prior, ReliaQuest's threat research team had shared intelligence on ShinyHunters, highlighting the group's use of fake domains and MFA bypass techniques. The screenshots of the compromised Okta dashboard, initially posted on X (formerly Twitter), were later deleted. The incident underscores the growing sophistication of social engineering attacks, even against cybersecurity providers. "id": "REL1787660926", "linkid": "reliaquest", "type": "Cyber Attack", "date": "8/2026", "severity": "25", "impact": "1", "explanation": "Attack without any consequences" {'affected_entities': [{'customers_affected': 'None', 'industry': 'Cybersecurity', 'name': 'ReliaQuest', 'type': 'Cybersecurity Firm'}], 'attack_vector': 'Fake Okta SSO page, MFA push manipulation, phone-based ' 'impersonation', 'data_breach': {'data_exfiltration': 'No', 'personally_identifiable_information': 'No', 'type_of_data_compromised': 'None'}, 'date_detected': '2026-08-23', 'date_publicly_disclosed': '2026-08-23', 'date_resolved': '2026-08-23', 'description': 'On 23 August 2026, cybersecurity firm ReliaQuest confirmed a ' 'social engineering attack linked to the ShinyHunters threat ' 'group, which attempted to breach its systems using a fake ' 'Okta Single Sign-On (SSO) page. The attackers, posing as IT ' 'support, tricked an employee into approving a multi-factor ' 'authentication (MFA) push during an impersonation call, ' 'granting them access to a view-only identity dashboard ' 'session. The breach was contained quickly due to ReliaQuest's ' 'layered security controls, including device-trust policies ' 'that restricted the attacker to a single session. No business ' 'applications, customer data, or company data were accessed, ' 'and no persistence was established. The compromised ' 'credentials were immediately expired and reset upon ' 'detection.', 'impact': {'data_compromised': 'None', 'operational_impact': 'Minimal (contained quickly)', 'systems_affected': 'Okta identity dashboard (view-only session)'}, 'initial_access_broker': {'backdoors_established': 'No', 'entry_point': 'Fake Okta SSO page, lookalike ' 'domain'}, 'investigation_status': 'Contained and resolved', 'lessons_learned': 'The incident underscores the growing sophistication of ' 'social engineering attacks, even against cybersecurity ' 'providers. Defense-in-depth strategies are critical, and ' 'phishing remains effective when attackers leverage ' 'employee names and urgency.', 'post_incident_analysis': {'corrective_actions': 'Credential reset, ' 'device-trust policies ' 'enforcement, enhanced ' 'monitoring', 'root_causes': 'Social engineering (MFA push ' 'manipulation), fake Okta SSO page, ' 'phone-based impersonation'}, 'recommendations': 'Implement layered security controls, enforce device-trust ' 'policies, and educate employees on social engineering ' 'tactics.', 'references': [{'source': 'ReliaQuest Threat Research Team'}, {'source': 'X (formerly Twitter)'}], 'response': {'containment_measures': 'Device-trust policies, credential ' 'expiration and reset', 'enhanced_monitoring': 'GreyMatter platform integration with ' 'Splunk, CrowdStrike, Fortinet, and ' 'Google Cloud Chronicle', 'incident_response_plan_activated': 'Yes', 'remediation_measures': 'Compromised credentials expired and ' 'reset'}, 'threat_actor': 'ShinyHunters', 'title': 'ReliaQuest Thwarts ShinyHunters Social Engineering Attack Targeting ' 'Okta SSO', 'type': 'Social Engineering', 'vulnerability_exploited': 'Human vulnerability (social engineering), ' 'potential WordPress plugin flaw (authentication ' 'bypass)'} Published by Cybersecurity Gaps Expose Australia's Transport and Logistics Sector Australia's transport and logistics industry a critical backbone for supply... Aug 25, 2026 Sotheby's International Investigates Cybersecurity Incident Involving Client Data Luxury real estate firm Sotheby's International is probing a cybersecurity... Aug 25, 2026 Historic McQuay Farmhouse Preserved Amid Charlotte's Growth; Preferred Parking Reports Data Breach Charlotte's Historic McQuay Farmhouse Stands as... Aug 24, 2026

AiThority
Jul 28th, 2026
ReliaQuest launches GreyMatter SIEM-Less, giving security teams detection speed and data optionality to outpace modern threats.

ReliaQuest launches GreyMatter SIEM-Less, giving security teams detection speed and data optionality to outpace modern threats. The new capability normalizes data, runs detections in motion, gives teams full control over where data lives, and enables queries from anywhere - without the cost and rigidity of a traditional SIEM. Jul 28, 2026 Prev Next 1 of 43,499 ReliaQuest, the global leader in Agentic AI cybersecurity, announced GreyMatter SIEM-Less, a new solution built for what enterprise security teams need now: faster detection and the flexibility to store their data in a more cost-effective tool they own, query it from anywhere in seconds and create reports as needed - without the cost and rigidity of a traditional SIEM. ReliaQuest will showcase GreyMatter SIEM-Less at Black Hat USA 2026. As AI enables adversaries to move faster and with data living in more places than ever, security teams are rethinking how they operate - how data moves, where it lives, how detections run, and how quickly they can take action. They need an architecture that delivers speed of detection before data is stored, full flexibility over their telemetry, and the ability to query from a single place regardless of the underlying infrastructure. GreyMatter SIEM-Less was built to meet that need. GreyMatter serves as the Agentic Defense for the enterprise, enabling defenders to detect threats, investigate, hunt, and respond across their entire tech stack. GreyMatter SIEM-Less builds on those capabilities by modernizing how security telemetry is handled end-to-end. This approach enables detections to run in seconds while preserving the outcomes security teams rely on - search, investigations, reporting, and response - with greater flexibility and lower cost. "We are in the middle of the great re-architecture of cybersecurity," said Brian Murphy, founder and CEO of ReliaQuest. "The most advanced security teams are rethinking how they store data, how they detect threats, and how quickly they can take action to stay ahead of agentic attacks. GreyMatter SIEM-Less provides the optionality and modularity they need to build the fastest, most accurate and cost-efficient architecture possible." As the security market undergoes this major shift, teams are looking for more flexible ways to manage telemetry at scale. SIEMs have long sat at the center of security operations, but that approach requires data to be sent, indexed, parsed, and stored before any detection can run, causing latency. As data has grown more distributed, centralizing everything in a single platform has become increasingly difficult to justify on cost or speed. Security teams need to detect threats at the source or in transit, route and drop data they don't need, and retain the functionality they rely on, such as saved searches, reporting, investigations, and long-term storage, without the cost that has often come with it. Security teams can interface with stored telemetry directly from GreyMatter using natural language, such as run searches, save searches, build reports, and conduct investigations and hunts, while preserving response actions from the same console (e.g., block an IP, ban a hash, and execute containment). The result is a more comprehensive defense model that unifies data movement, detection, investigation, and response without speed and cost tradeoffs.

Recently Posted Jobs

Sign up to get curated job recommendations

ReliaQuest is Hiring for 13 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →