---
title: "Questel Confirms Breach After ShinyHunters Leaks Stolen Data"
date: 2026-08-13
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/08/questel-confirms-vishing-breach.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Questel Confirms Breach After ShinyHunters Leaks Stolen Data

Questel confirmed on August 13, 2026, that attackers reached part of its Microsoft 365 environment through a voice phishing call and that some stolen data is online. The French IP firm’s admission came nine days after ShinyHunters’ extortion deadline expired.

## What to Know?

- Questel says a voice phishing call gave attackers entry to a Sales SharePoint site inside its Microsoft 365 environment.
- ShinyHunters claims more than 21 million records with some personal data and over 147GB of internal corporate files.
- The group listed Questel on August 1 alongside Alcon and Lumenis, with an August 4 contact deadline.
- Questel has told CNIL, the French data regulator, filed criminal complaints, and is contacting affected customers.

## How It Happened?

Attackers phoned their way in. Questel told **CyberInsider** on August 13 that it recently identified unauthorized access to part of its Microsoft 365 environment, specifically a Sales SharePoint site, after a [voice phishing](https://sqmagazine.co.uk/phishing-email-statistics/) attempt, a call in which an attacker poses as trusted personnel to extract credentials or an approved authentication prompt.

The company says the access is contained, with no evidence of lingering intruder presence. Production IP platforms and SaaS services were never accessed, and operations kept running while outside specialists assist the investigation.

## ShinyHunters Says Salesforce, Questel Says SharePoint

The two accounts name different systems. ShinyHunters, the group behind a recent [Vimeo data breach](https://sqmagazine.co.uk/vimeo-breach-user-data-vendor-hack/), bills the haul as [Salesforce records](https://sqmagazine.co.uk/salesforce-statistics/); Questel’s confirmation covers only SharePoint. “**We are conducting a detailed forensic review of the published material**,” Questel said, declining to endorse the 21 million figure. It has not said how the call became working access, how long the intruders stayed, or which data categories were exposed.

## SQ Magazine’s Takeaway

The entry point is the story. Questel manages patent and trademark portfolios for corporations and law firms, yet one persuaded employee and a single **SharePoint** site handed an extortion crew material it now offers for download. The silence between the lapsed deadline and a confirmation prompted by a journalist’s query will not sit well with clients carrying their own notification duties.

Next, the forensic review will show what the published files contain, and CNIL’s involvement could bring findings under **GDPR**. Questel clients should assume contact details tied to sales relationships are out. Treating unexpected calls or emails that mention filings, renewals, or invoices with suspicion helps reduce follow on phishing risk, and verifying payment or credential requests through a known channel does the same.