Questel Microsoft 365 breach via vishing (ShinyHunters extortion)
French intellectual property management company Questel confirmed that a voice-phishing attack gave ShinyHunters access to part of its Microsoft 365 environment, after the group leaked data that breach indexes tie to about 1.7 million records.
- Victim
- Questel SAS
- records
- 1.7M
On 13 August 2026, Questel (a French company that manages patent and trademark portfolios for corporations and law firms) confirmed that attackers had gained unauthorized access to part of its Microsoft 365 environment after a voice-phishing (vishing) call aimed at an employee's credentials. The intruders reached a Sales SharePoint site and exfiltrated its contents.
The confirmation followed the extortion group ShinyHunters listing Questel on its data-leak site at the start of August with a 4 August payment deadline. When the deadline passed, the group published the stolen material. ShinyHunters claimed more than 21 million Salesforce records and 147 GB of internal files; Questel declined to confirm that figure, and the company's own account of a SharePoint entry point does not fully match the attacker's Salesforce claim.
What was exposed
Breach index XposedOrNot later catalogued 1,744,241 records from the leak, with roughly 1.7 million unique email addresses alongside physical addresses, dates of birth and phone numbers. Questel said its production IP platforms and SaaS services were not affected, that there was no evidence of lingering intruder presence, and that it was running a forensic review of the published data. The company notified France's data protection authority, the CNIL, filed criminal complaints and began contacting affected customers.
Why it matters
Questel holds sensitive commercial information about its clients' patent and trademark strategies, which makes its customer and sales data valuable well beyond the contact details themselves. The intrusion follows the 2026 ShinyHunters playbook seen at McKesson, RingCentral and others: no software exploit, just a convincing phone call to an employee, followed by bulk extraction from cloud collaboration and CRM tools and a pay-or-leak demand.
Timeline
ShinyHunters lists Questel on its data-leak site with an extortion deadline of 4 August.
Questel confirms that a vishing attack gave intruders access to part of its Microsoft 365 environment and that data has been published.
Breach index XposedOrNot adds the leaked dataset, counting 1,744,241 records.
Sources
- sqmagazine.co.ukhttps://sqmagazine.co.uk/questel-confirms-vishing-breach-shinyhunters-leak/
- xposedornot.comhttps://xposedornot.com/breach/Questel
- dexpose.iohttps://www.dexpose.io/shinyhunters-breach-questel-sas-french-ip-giant-under-siege/