Questel, a French intellectual property software and services company, had data on approximately 1.2 million accounts published by the ShinyHunters group following an extortion campaign in August 2026.
Loading page…
Loading page…
Questel, a French intellectual property software and services company, had data on approximately 1.2 million accounts published by the ShinyHunters group following an extortion campaign in August 2026.
According to Have I Been Pwned, in August 2026 the ShinyHunters threat group targeted Questel with a "pay or leak" extortion campaign. After the company did not comply, the group published a large dataset they claimed was obtained from Questel's systems.
Reported by HIBP, the leaked data primarily consisted of corporate contact information tied to sales leads, support cases, and marketing activities. Exposed fields include names, email addresses, employers, job titles, physical addresses, phone numbers, and support ticket data.
Approximately 1.2 million unique email addresses were found in the dataset, according to HIBP. Those affected appear to be business contacts — customers, prospects, and others who interacted with Questel through sales or support channels.
If you have ever provided contact information to Questel, be alert for phishing emails and unsolicited calls, as your name, employer, job title, and contact details may be in circulation. Consider being cautious with unexpected messages that reference your employer or job role, as attackers could use this information to craft convincing targeted scams.