ConfirmedData breach

Questel: a data breach

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

The record

Organisation
Questel
Identity
Questelidentified by its domain in a verified breach record
Records affected
1,226,209 records
Data exposed
Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets
Sector
Not recorded
Occurred
2026-08-01
Disclosed
2026-09-01
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-09-01