SecuritySeptember 7, 20267 min read

What to Do After the Questel Data Breach (2026)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Questel Data Breach (2026)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

Questel, the French intellectual property software and services company, was hit by a ShinyHunters extortion campaign in August 2026. The stolen data was published and added to Have I Been Pwned on September 1, 2026, exposing 1,226,209 unique email addresses along with names, employers, job titles, physical addresses and phone numbers. Here is exactly what to do now.

What Happened in the Questel Breach

Questel SAS is a Paris-based provider of intellectual property software and services — patent search, trademark management, IP renewals and translation — used by law firms, corporate legal departments and R&D teams worldwide. In August 2026 the company became one of several targets in the ShinyHunters "pay or leak" extortion wave that swept through companies using cloud CRM and collaboration platforms.

Questel confirmed on August 13, 2026 that attackers reached part of its Microsoft 365 environment following a voice phishing (vishing) call — an attacker phoned an employee, impersonated internal IT, and talked them into granting access. The company said the confirmed unauthorized access involved a sales SharePoint environment. ShinyHunters claimed far more: more than 21 million records containing personally identifiable information plus roughly 147 GB of internal corporate data.

When the ransom was not paid, the group published the data. Have I Been Pwned loaded the corpus on September 1, 2026 at 1,226,209 unique email addresses.

What Data Was Exposed

The published corpus is largely corporate contact information drawn from sales leads, support cases and marketing activity. Confirmed data classes include:

  • Email addresses — mostly work addresses
  • Full names
  • Employers and job titles
  • Physical addresses — largely business addresses
  • Phone numbers

No passwords, payment card numbers or government ID numbers have been reported in the published set. That is genuinely good news — but the combination that was leaked is close to ideal for social engineering.

Why "Just Business Contact Data" Is Still Dangerous

Name + employer + job title + direct phone + work email is the exact recipe for business email compromise and vishing — the same technique used to breach Questel itself. Attackers now know who at your company handles IP filings, who signs off on renewals, and what to say to sound legitimate. Expect calls and emails that reference real invoices, real docket numbers and real colleagues.

Step 1: Check Whether Your Address Is in the Corpus

Search your work and personal email addresses on haveibeenpwned.com. If "Questel" appears in your results, your record was in the published dump. Check every address you have ever used with an IP vendor, including aliases and role addresses like ip@ or patents@ at your company. If you manage a team, ask your IT or security group to run a domain-wide check.

Step 2: Warn Your Team About Vishing Before Anything Else

The attack that started this breach was a phone call. The follow-on attacks will be too. Tell colleagues, in writing, this week:

  • Nobody from IT, Questel, or any vendor will ever phone and ask you to approve an MFA prompt, read out a code, or install a remote-access tool.
  • If a caller creates urgency — a deadline, a lapsed filing, a locked account — hang up and call back on a number you already have.
  • Report every suspicious call, even the ones you handled correctly. Attackers dial many people until one says yes.

Step 3: Turn On Phishing-Resistant MFA

Push-notification and SMS second factors are exactly what a vishing caller talks you past. Move Microsoft 365, Google Workspace and any IP-docketing system to hardware security keys or passkeys, which cannot be relayed over a phone call. Where hardware keys are not possible, switch to number-matching authenticator prompts rather than simple "approve/deny" pushes.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 4: Change Reused Passwords

No passwords were published, but Questel-linked email addresses will now be fed into credential-stuffing tools against every other service. If you reused your work password anywhere — a vendor portal, a conference site, a personal account — change it now. Use a password manager and a unique passphrase per site.

Step 5: Watch for Invoice and Renewal Fraud

IP renewals involve real, recurring, high-value payments to foreign entities — a fraudster's dream. For the next several months:

  • Verify any change of bank details for an IP vendor by phone, on a number from your own records, with a person you know.
  • Treat "urgent renewal deadline" emails as hostile until confirmed in your docketing system directly.
  • Require dual approval on payments to new or changed beneficiaries.

Step 6: Exercise Your GDPR Rights

Questel is headquartered in France, so the GDPR applies. You can ask Questel for a copy of the personal data it holds on you (Article 15), ask for corrections (Article 16), and ask for erasure where there is no ongoing legal basis (Article 17). Questel must respond within one month. If you are in the EU or UK, you can also complain to your national data protection authority — the CNIL in France, the ICO in the UK.

Step 7: Cut Off the Data Brokers Amplifying the Leak

A breach corpus becomes far more dangerous when it is joined to other data. Attackers routinely enrich a leaked work profile with your home address, personal mobile, relatives and property records — all of which people-search sites and B2B data brokers sell openly. Questel-leaked records will be cross-referenced against exactly those sources.

Removing yourself from those brokers breaks the join. It stops your work identity from being linked to your home life, which is what turns a corporate contact leak into targeted fraud, harassment or SIM-swap attempts against you personally.

Close the Loop After the Breach

PrivacyOn removes your personal information from 100+ data brokers and people-search sites, monitors the dark web 24/7 for your details appearing in new dumps like this one, and covers up to 5 family members from $8.33/month. Start with a free scan to see exactly where you are exposed right now.

Frequently Asked Questions

Was the Questel breach confirmed?

Yes. Questel publicly confirmed on August 13, 2026 that attackers accessed part of its Microsoft 365 environment after a voice phishing call, and that some stolen data had been published. Have I Been Pwned verified and loaded the corpus on September 1, 2026 at 1,226,209 unique email addresses.

How many people were affected by the Questel data breach?

Have I Been Pwned lists 1,226,209 unique email addresses in the published data. ShinyHunters claimed a far larger haul — over 21 million records and around 147 GB of internal data — but the verified, published corpus is the 1.2 million figure.

Were passwords or credit cards exposed?

No passwords, payment card numbers or government ID numbers have been reported in the published Questel data. The exposed classes are email addresses, names, employers, job titles, physical addresses and phone numbers — business contact information rather than credentials.

I never signed up with Questel. Why is my email in the breach?

The corpus came from sales, marketing and support systems, so it includes people who were prospects, event contacts or support requesters rather than customers. If a colleague submitted your details on a form, or your address was bought as a sales lead, you can appear without ever having used the product.

What should I do first after the Questel breach?

Check your addresses on Have I Been Pwned, then warn your team about vishing and switch your work accounts to phishing-resistant MFA such as passkeys or hardware keys. Those two steps block the attack pattern that caused this breach and the follow-on attacks that use its data.

Can I get my leaked information taken down?

You cannot recall data that criminals have published, but you can shut down the legal sources attackers use to enrich it. Filing a GDPR erasure request with Questel handles their copy; a removal service like PrivacyOn clears your home address, phone number and relatives from the 100+ data brokers that would otherwise let someone turn a work email into a full profile of you.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families