Full Report
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
Analysis Summary
# Incident Report: Questel Extortion and Data Leak
## Executive Summary
In August 2026, the French intellectual property firm Questel fell victim to a "pay or leak" extortion campaign orchestrated by the threat group ShinyHunters. The incident, initiated via a vishing (voice phishing) attack, resulted in the exfiltration and subsequent public leak of a database containing 1.2 million unique records. The compromised data primarily consists of corporate contact information and support ticket history.
## Incident Details
- **Discovery Date:** August 2026 (via extortion threat)
- **Incident Date:** August 2026
- **Affected Organization:** Questel
- **Sector:** Intellectual Property Software and Services
- **Geography:** France (Global clients)
## Timeline of Events
### Initial Access
- **Date/Time:** August 2026
- **Vector:** Vishing (Voice Phishing)
- **Details:** Attackers utilized social engineering via telephone to deceive employees and gain initial entry into the corporate environment.
### Lateral Movement
- **Details:** Specific lateral movement techniques were not publicly disclosed, though the attackers successfully pivoted from the initial point of entry to marketing and support databases.
### Data Exfiltration/Impact
- **Details:** The threat actors exfiltrated a large corpus of data related to sales leads, support cases, and marketing activities. Following a failed extortion attempt, the data was published online.
### Detection & Response
- **How it was discovered:** The incident was identified when ShinyHunters contacted the company for extortion and subsequently leaked the data.
- **Response actions taken:** Questel confirmed the breach and initiated investigations into the vishing vector; data was indexed by breach notification services (HIBP) by September 1, 2026.
## Attack Methodology
- **Initial Access:** Vishing (Voice Phishing / Social Engineering)
- **Persistence:** Not disclosed
- **Privilege Escalation:** Not disclosed
- **Defense Evasion:** Use of human-centric social engineering to bypass technical controls.
- **Credential Access:** Likely obtained via vishing deception.
- **Discovery:** Targeted CRM, support databases, and marketing repositories.
- **Lateral Movement:** Not disclosed.
- **Collection:** Aggregation of support tickets and lead lists.
- **Exfiltration:** Transfer of 1.2M unique email records and associated PII.
- **Impact:** Data leak and extortion (Pay-or-Leak).
## Impact Assessment
- **Financial:** Potential regulatory fines (GDPR) and costs associated with incident response and remediation.
- **Data Breach:** 1.2 million unique email addresses, names, job titles, employers, physical addresses, phone numbers, and support ticket contents.
- **Operational:** Disruption to marketing and support departments; requirement for company-wide credential resets.
- **Reputational:** High; exposure of B2B client contact details and internal support interactions.
## Indicators of Compromise
- **Network indicators:** None disclosed in the public report.
- **File indicators:** Database exports containing Questel client information.
- **Behavioral indicators:** Unusual phone-based inquiries targeting employees for credentials or system access (Vishing).
## Response Actions
- **Containment measures:** Identification and isolation of the targeted entry point.
- **Eradication steps:** Review of access logs and termination of compromised sessions.
- **Recovery actions:** Notification to affected parties and security hardening of identity management systems.
## Lessons Learned
- **Key takeaways:** Social engineering remains a highly effective bypass for robust technical perimeters.
- **What could have been done better:** Implementation of stricter identity verification for internal support calls and enhanced employee training regarding vishing tactics.
## Recommendations
- **Employee Training:** Conduct regular Security Awareness Training (SAT) specifically focusing on vishing and social engineering.
- **Multi-Factor Authentication (MFA):** Enforce hardware-based MFA (e.g., FIDO2 keys) to mitigate the success of credential harvesting via phishing/vishing.
- **Least Privilege:** Restrict access to marketing and support databases to ensure that a single compromised account cannot exfiltrate the entire customer corpus.
- **Call Verification:** Implement a formal "call-back" or out-of-band verification process for internal requests involving sensitive information or access changes.