French intellectual property services provider Questel has confirmed that attackers gained unauthorized access to part of its Microsoft 365 environment after a voice phishing attempt, and that some of the stolen data has since been published online. The company made the admission to CyberInsider on August 13, 2026, after being contacted about a ShinyHunters leak site post naming Questel SAS. The extortion group claims more than 21 million records containing some personally identifiable information along with over 147GB of internal corporate data. Questel has confirmed the intrusion and its entry vector but has pointedly declined to endorse the attacker's numbers, saying it is still conducting a forensic review of the published material.
What Happened
According to Questel's own statement, the company "recently identified unauthorized access to part of our Microsoft 365 environment, specifically a Sales SharePoint environment, following a voice phishing attempt." The company says the unauthorized access has been contained, that there is currently no evidence the attackers retain access, and that outside specialists are assisting the investigation.
Questel drew a hard line around its production estate: "None of our production tools, IP platforms, or SaaS IP products and services have been accessed, and our operations have remained fully operational." That distinction matters for an IP services firm whose customers entrust it with patent and trademark portfolios, but it is a claim that rests on the company's own forensics and has not been independently verified.
The timeline reconstructed by SQ Magazine puts ShinyHunters' listing of Questel on August 1, 2026, alongside Alcon and Lumenis, with an August 4 contact deadline. Undercode News reported alleged Questel data circulating on underground channels on August 6, citing the monitoring account Dark Web Intelligence, at a point when Questel had not publicly confirmed any incident. The company's confirmation landed on August 13, nine days after the extortion deadline expired.
Questel has told CNIL, the French data protection regulator, filed criminal complaints, and is contacting affected customers, per SQ Magazine's account.
What Was Taken
The figures do not line up, and the gap is wide enough that defenders should treat every number as unsettled.
ShinyHunters' leak site claims over 21 million records with some PII plus more than 147GB of internal corporate files, a figure reported by both CyberInsider and SQ Magazine from the listing itself. Questel has declined to endorse that count.
Undercode News, an OTHER-tier source, headlined "more than 11 million records" while its own body text describes a forum advertisement containing approximately 1,131,033 unique email addresses, with sample records including CRM case management entries, support tickets, customer contact information and lead management records under table names such as "questel_cases" and "questel_leads." That internal inconsistency, roughly 1.13 million unique addresses versus an 11 million headline versus the actor's own 21 million record claim, is a reminder that raw record counts, unique email counts and marketing numbers are three different things. Undercode itself notes the dataset had not been independently verified.
There is also a disagreement about which system was hit. ShinyHunters bills the haul as Salesforce records; Questel's confirmation covers only a Sales SharePoint environment inside Microsoft 365. Both can be partially true if data was exported between platforms, but on the public record the accounts genuinely differ, and no source resolves it.
For scale calibration against sibling incidents, TechNadu reports that ShinyHunters-linked datasets for Brinks Home and Alcon, both loaded into Have I Been Pwned, contained 732,162 and 218,395 unique email addresses respectively, well below the headline record counts those listings advertised.
Why It Matters
Questel sits upstream of a lot of sensitive commercial activity. Its customers are corporations, research organizations and law firms whose patent and trademark work is competitively valuable long before it becomes public. Even if the compromise is confined to a sales SharePoint site, CRM cases, leads and support tickets from an IP services provider expose client relationships, procurement discussions and named contacts across a portfolio of enterprises. That is high grade material for follow-on social engineering against those same clients.
The incident also fits a pattern that has defined 2026. Cybersecurity Insiders, summarizing TechCrunch's mid-year breach roundup, traces the year's highest-damage intrusions to aged credentials, weak helpdesk identity verification and access lifecycle gaps rather than to novel exploits. ShinyHunters reached Instructure's Canvas platform the same way, exposing data on more than 30 million students and staff, then returned for a second breach after Instructure initially refused to pay. Health-ISAC issued a July 24 advisory warning of a measurable rise in successful ShinyHunters attacks against healthcare and medical technology organizations.
There is a downstream cost too. BleepingComputer documented a campaign in which unrelated threat actors harvested email addresses from previously leaked ShinyHunters datasets, including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill, and used them to send sextortion emails demanding $2,000 in Bitcoin. ShinyHunters denied involvement when contacted. Victim organizations should expect their exposed contacts to be recycled by opportunists regardless of whether the original extortion is resolved.
The Attack Technique
The entry vector Questel describes matches the ShinyHunters playbook precisely. Per the Health-ISAC advisory summarized by BleepingComputer, the chain begins with voice phishing to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices. The group has been observed using custom phishing kits purpose built for voice-based operations.
Once an account is taken over, the payoff is the single sign-on dashboard. Attackers log into the victim's Okta, Microsoft Entra or Google SSO portal, which enumerates every SaaS application that user can reach: Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive and more. For a data theft and extortion crew, that dashboard converts one compromised identity into a map of the company's cloud data. It also explains how a single intrusion can plausibly touch both SharePoint and Salesforce, and why the Questel and ShinyHunters accounts may be describing different stops on the same path.
Questel has not said how the phone call became working access, how long the attackers were inside, or when the intrusion began. Those gaps are material and remain open.
What Organizations Should Do
- Harden the helpdesk. Require out-of-band identity verification before any password reset, MFA method change or new device enrollment. Manager or supervisor callback approval for MFA resets removes the single highest-value lever ShinyHunters pulls.
- Move to phishing-resistant MFA. FIDO2 security keys and passkeys defeat the push-approval and credential-relay outcomes that vishing calls are designed to produce. Disable SMS and voice as fallback factors where possible.
- Treat the SSO dashboard as a crown jewel. Scope application tiles per user, enforce conditional access on high-value SaaS apps, and alert on a single identity accessing multiple SaaS applications it has never touched before within a short window.
- Instrument SharePoint and CRM for bulk export. Mass download, large-scale search, and bulk record export are the observable stage between account takeover and extortion. Rate-limit them and alert on anomalies rather than relying on login telemetry alone.
- Audit dormant and legacy credentials. The Klue compromise reported by Cybersecurity Insiders turned on a pilot credential issued in 2022 and never decommissioned, opening a four-year window that reached close to 200 enterprise customers. Run access lifecycle reviews with the assumption that unused equals exploitable.
- Prepare the downstream notification path in advance. If your CRM holds client contacts, a breach becomes their problem too. Have counsel, regulator notification and customer communications ready, and warn exposed contacts that leaked addresses get recycled into sextortion and fraud campaigns by third parties.
- Verify vendor claims independently. If Questel is in your supply chain, ask for the forensic scope in writing rather than accepting the public statement that production IP platforms were untouched.
Sources: Questel confirms Microsoft 365 breach after ShinyHunters leaks data | Health-ISAC warns of rising ShinyHunters data theft attacks on heal... | ShinyHunters data leaks fuel $2,000 sextortion email scam | Questel Confirms Vishing Breach After ShinyHunters Leak | Questel Customer Data Allegedly Exposed on the Dark Web, More Than... | Stale Credentials Behind 2026s Worst Data Breach Incidents | ShinyHunters Data Leaks Expose Nearly 1 Million Brinks Home and Alc... | Questel SAS Data Breach Raises New Cybersecurity Concerns as Dark W...