ConfirmedData breach
Questel: a data breach
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
The record
- Organisation
- Questel →
- Identity
- Questelidentified by its domain in a verified breach record
- Records affected
- 1,226,209 records
- Data exposed
- Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets
- Sector
- Not recorded
- Occurred
- 2026-08-01
- Disclosed
- 2026-09-01
- First recorded here
- 2026-09-09
Sources (1)
One source so far.
- Have I Been Pwned ↗First reported
2026-09-01