Questel Breach: 1.2M Business Contacts Exposed (2026)
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact inf...
Overview
In August 2026, French intellectual property software firm Questel became the target of a ShinyHunters “pay or leak” extortion campaign. The notorious threat group published a massive corpus of data allegedly stolen from the company, containing over 1.2 million unique email addresses. The dataset is largely composed of corporate contact information tied to sales leads, support cases, and marketing activities, including names, employers, and job titles, alongside physical addresses and phone numbers.
This is not a typical consumer credential dump. The exposed records are B2B in nature, meaning the affected individuals are primarily professionals who interacted with Questel’s IP management and patent services. The breach was reported to Have I Been Pwned, giving affected users a direct way to verify exposure.
What Was Exposed
The leaked dataset contains six distinct data points per record:
- Email addresses (1,226,209 unique) - The core identifier tying all other data together
- Names - Full personal names associated with each account
- Phone numbers - Direct and mobile lines
- Physical addresses - Business and personal locations
- Employers - Company names and organizational affiliations
- Job titles - Professional roles and seniority indicators
The absence of passwords, financial data, or government IDs is notable. This is a professional contact database, not a credential store. However, the combination of employer, title, and direct contact details creates a hazard that goes beyond typical spam.
How the Breach Happened
ShinyHunters operates on an extortion-first model. The group infiltrates corporate networks, exfiltrates large data volumes, and then demands payment to prevent public release. When Questel did not meet their demands, the group published the full corpus on dark web forums.
The attack surface was likely a misconfigured cloud database or an exposed API tied to Questel’s customer relationship management system. The data structure, dominated by sales leads and support tickets, suggests the attackers accessed the company’s marketing and CRM infrastructure rather than core intellectual property databases.
Account Takeover Risks
While no passwords were exposed, the risk is not zero. Many professionals reuse passwords across personal and work accounts. If any employee or lead used the same email address with a password from a previous breach, attackers could attempt credential stuffing against corporate portals, VPNs, or email systems.
The exposed job titles and employers enable highly targeted phishing. A message appearing to come from a colleague or IT department, referencing the recipient’s actual employer and role, has significantly higher success rates than generic spam.
What to Do Right Now
Even without exposed passwords, the data is live ammunition for social engineering. Take these steps:
- Check your exposure on Have I Been Pwned. Enter the email address you used with Questel or its services.
- Enable multi-factor authentication on all work email accounts and any portal that uses your exposed email as the login identifier. MFA blocks the majority of credential-stuffing attempts.
- Treat unsolicited calls and emails with suspicion. If someone references your employer, title, or a recent interaction that could relate to IP services, verify through a known official channel before responding or clicking links.
- Update your professional profile privacy settings on LinkedIn and corporate directories. Minimize publicly visible data that could combine with the leaked records.
- Watch for business email compromise attempts. Attackers may impersonate your employer or Questel contacts to request wire transfers, invoice payments, or sensitive documentation.
Security Insight
This breach reveals a persistent blind spot in B2B security: sales and marketing data is treated as low-sensitivity, yet it is a goldmine for social engineers. Questel’s failure to segment or encrypt this CRM data allowed a single intrusion to expose over a million professional profiles. Unlike consumer breaches that grab headlines, corporate contact databases rarely face regulatory scrutiny, which is why groups like ShinyHunters continue to target them. The lesson for enterprises is clear: treat every database containing personal identifiers, even “just business contacts,” with the same rigor as core systems, because attackers are already mining it for the next phishing campaign.
Further Reading
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompass...
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, ...
In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included nam...
In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, which exposed 4.9M unique email addresses alo...