Questel SAS Data Breach

Alleged

Ransomware claim involving Questel SAS

Published: Aug 2, 2026 ShinyHunters
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Questel SAS
Industry
Business Services
Threat Actor
ShinyHunters
Date of Incident
Aug 2, 2026

Executive Summary

On August 2, 2026, the extortion group ShinyHunters added Questel SAS to its dark web leak site. SOCRadar’s Dark Web Monitoring service detected this listing. While the exact sector of Questel SAS is not detailed, its operations are based in France. This listing appears to be part of a steady stream of activity from ShinyHunters, rather than a significant surge. In the 60 days preceding this listing, ShinyHunters claimed 18 other victims. The group’s recent targeting has predominantly focused on the Technology, Education, and Consumer Services sectors, with a notable concentration of victims in the United States, France, and Switzerland. Other recent French victims claimed by ShinyHunters include Ernst & Young, RingCentral, Inc., BH Security, LLC, and Ingram Content Group, Inc. This geographic distribution aligns with the group’s established operational footprint, though its sector targeting shows some variability, which is a factor to consider for sector-specific risk assessments.

Technical Analysis

SOCRadar’s stealer-log telemetry revealed a significant exposure related to the questel[.]com domain. The analysis identified ten records representing internal employee authentication against organization-owned or federated systems, three records linked to customers or third-party users accessing Questel systems, and three corporate accounts on external services. The critical endpoints flagged include the Microsoft 365 tenant identity provider and the company’s Salesforce tenant and login infrastructure, which are primary targets for attackers seeking access to sensitive data such as emails, collaboration tools, and customer relationship management information. The telemetry data indicates a mixed profile of compromise, suggesting both endpoint compromise and direct corporate identity exposure may have occurred. The log dates range from June 3, 2026, to July 28, 2026, with the most recent records surfacing just days before the leak-site listing. This temporal proximity is noteworthy, although the telemetry does not definitively confirm that these specific exposures directly led to the data extortion incident. These observed credential exposures should be treated as an independent finding that warrants remediation, regardless of their direct link to the ShinyHunters listing. While ShinyHunters is primarily a data extortion group and its attack vectors may differ from encryption-focused ransomware groups (often favoring social engineering or large-scale credential abuse), any exposed corporate credentials pose a significant security risk. It is recommended that Questel SAS conduct thorough credential hygiene checks, review multi-factor authentication status, monitor for activity on alternate corporate domains, and scrutinize access logs for Microsoft 365, VPNs, and remote access portals.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.