High

Questel Breach: 1.2M Business Contacts Exposed (2026)

By Yazoul AI · automated

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact inf...

Overview

In August 2026, French intellectual property software firm Questel became the target of a ShinyHunters “pay or leak” extortion campaign. The notorious threat group published a massive corpus of data allegedly stolen from the company, containing over 1.2 million unique email addresses. The dataset is largely composed of corporate contact information tied to sales leads, support cases, and marketing activities, including names, employers, and job titles, alongside physical addresses and phone numbers.

This is not a typical consumer credential dump. The exposed records are B2B in nature, meaning the affected individuals are primarily professionals who interacted with Questel’s IP management and patent services. The breach was reported to Have I Been Pwned, giving affected users a direct way to verify exposure.

What Was Exposed

The leaked dataset contains six distinct data points per record:

  • Email addresses (1,226,209 unique) - The core identifier tying all other data together
  • Names - Full personal names associated with each account
  • Phone numbers - Direct and mobile lines
  • Physical addresses - Business and personal locations
  • Employers - Company names and organizational affiliations
  • Job titles - Professional roles and seniority indicators

The absence of passwords, financial data, or government IDs is notable. This is a professional contact database, not a credential store. However, the combination of employer, title, and direct contact details creates a hazard that goes beyond typical spam.

How the Breach Happened

ShinyHunters operates on an extortion-first model. The group infiltrates corporate networks, exfiltrates large data volumes, and then demands payment to prevent public release. When Questel did not meet their demands, the group published the full corpus on dark web forums.

The attack surface was likely a misconfigured cloud database or an exposed API tied to Questel’s customer relationship management system. The data structure, dominated by sales leads and support tickets, suggests the attackers accessed the company’s marketing and CRM infrastructure rather than core intellectual property databases.

Account Takeover Risks

While no passwords were exposed, the risk is not zero. Many professionals reuse passwords across personal and work accounts. If any employee or lead used the same email address with a password from a previous breach, attackers could attempt credential stuffing against corporate portals, VPNs, or email systems.

The exposed job titles and employers enable highly targeted phishing. A message appearing to come from a colleague or IT department, referencing the recipient’s actual employer and role, has significantly higher success rates than generic spam.

What to Do Right Now

Even without exposed passwords, the data is live ammunition for social engineering. Take these steps:

  1. Check your exposure on Have I Been Pwned. Enter the email address you used with Questel or its services.
  2. Enable multi-factor authentication on all work email accounts and any portal that uses your exposed email as the login identifier. MFA blocks the majority of credential-stuffing attempts.
  3. Treat unsolicited calls and emails with suspicion. If someone references your employer, title, or a recent interaction that could relate to IP services, verify through a known official channel before responding or clicking links.
  4. Update your professional profile privacy settings on LinkedIn and corporate directories. Minimize publicly visible data that could combine with the leaked records.
  5. Watch for business email compromise attempts. Attackers may impersonate your employer or Questel contacts to request wire transfers, invoice payments, or sensitive documentation.

Security Insight

This breach reveals a persistent blind spot in B2B security: sales and marketing data is treated as low-sensitivity, yet it is a goldmine for social engineers. Questel’s failure to segment or encrypt this CRM data allowed a single intrusion to expose over a million professional profiles. Unlike consumer breaches that grab headlines, corporate contact databases rarely face regulatory scrutiny, which is why groups like ShinyHunters continue to target them. The lesson for enterprises is clear: treat every database containing personal identifiers, even “just business contacts,” with the same rigor as core systems, because attackers are already mining it for the next phishing campaign.

Further Reading

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.