Questel breach listed 1.2M email addresses

Published September 1, 2026

Questel had customer data stolen in a breach affecting 1.2M accounts. The exposed data included Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets.

Report priority
High
Involves
Questel

What is known

ShinyHunters stole and leaked data from Questel.

What to do

Search your email address in Have I Been Pwned for the Questel breach. If it appears, treat Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets as exposed.

Follow Questel notices, watch health insurance and identity records for misuse, and replace any reused password tied to the exposed email address.

Reported details

Have I Been Pwned lists the Questel breach as affecting 1.2M accounts. It attributes the incident to a ShinyHunters pay-or-leak extortion campaign. The listed data classes are Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets.