Questel Data Breach (September 2026)
Questel, a French intellectual property software and services firm, was breached in August 2026 in a ShinyHunters extortion campaign that exposed 1,226,209 records of business contact data including names, work email addresses, employers, job titles, phone numbers and support tickets.
- Organization
- Questel
- Sector
- Professional services
- Country
- France
- Incident date
- August 1, 2026
- Disclosed
- September 1, 2026
- Records affected
- 1.2 million
- Attack type
- Social engineering
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Employers
- Job titles
- Names
- Phone numbers
- Physical addresses
- Support tickets
- The incident date recorded for the breach on the Have I Been Pwned listing.
- Questel confirms unauthorized access to a Sales SharePoint environment inside its Microsoft 365 tenant following a voice phishing attempt, as reported by CyberInsider.
- Have I Been Pwned loads the verified records.
What Happened
Questel, the French intellectual property software and services company, was named in a ShinyHunters extortion campaign in August 2026, per the Have I Been Pwned entry. The group later published a large body of data it said came from the company, and Have I Been Pwned has since verified and loaded 1,226,209 records drawn from it. The listing describes the material as corporate contact information tied to sales leads, support cases and marketing activity.
Questel confirmed on August 13, 2026 that attackers reached part of its Microsoft 365 environment, specifically a Sales SharePoint environment, following a voice phishing attempt, as reported by Amar Ćemanović for CyberInsider. The company said the access had been contained, that it saw no evidence the attackers retained access, and that production systems were not affected. It reported the incident to the French regulator CNIL and filed police complaints, according to the same report.
ShinyHunters claimed to hold more than 21 million records and over 147GB of corporate data, figures CyberInsider reported the company had not verified while its forensic review continued. The fields loaded by Have I Been Pwned are names, email addresses, phone numbers, physical addresses, employers, job titles and support tickets. No passwords and no payment data appear in the published listing.
What Was Exposed
7 classes of data across 1,226,209 records, per Have I Been Pwned: Questel breach listing: email addresses, employers, job titles, names, phone numbers, physical addresses and support tickets.
A record that pairs a working business email address with a name, employer, job title, phone number and the contents of a past support ticket gives an attacker everything needed to impersonate a vendor or a colleague convincingly in a targeted call or message.
What to Do If You Are Affected
The full sequence, and what to do in what order, is in what to do after a data breach.
What Is Not Known Yet
Questel has not said how long the attackers had access, which categories of information it believes were taken, or how many people it is notifying. Neither the company nor Have I Been Pwned has addressed the group's claim of 21 million records.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.