Breach Database / Questel

Yes — Questel was breached.

What happened

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

What data was exposed

What to do right now

  1. Be alert for smishing and SIM-swap attempts. Treat unexpected texts and "carrier" calls with suspicion; add a PIN/port-freeze with your mobile carrier.
  2. Watch for targeted phishing mail. A leaked home address makes postal and doorstep scams more convincing.
  3. Expect convincing phishing emails. Attackers use breached details to write personalized emails. Be suspicious of any message referencing this service.
  4. Check your other accounts on Have I Been Pwned. Your email address may appear in other breaches you don't know about yet.
  5. Monitor the apps you use going forward. Clearly watches the breach record for the companies behind your apps and alerts you the moment one appears.

Breach data from Have I Been Pwned. Listing here means the service appears in the public breach record — not that your personal data was affected.