Shinyhunters ransomware claims Questel SAS

Published August 1, 2026

Extortion attackers calling themselves Shinyhunters say they broke into Questel, a company that manages patents and trademarks for other businesses.

Report priority
High
Named organization
Questel SAS
Group
Shinyhunters

What is known

The attackers say they pulled millions of records out of Questel's Salesforce customer database and copied over 147GB of internal company files, then used the stolen data as leverage to demand payment.

What to do

If you are a client, patent holder, or employee whose information was handled through Questel's Salesforce system, watch for a breach notice from Questel and treat unexpected emails claiming to be from Questel or referencing this leak with caution until the company confirms what data was taken.

Reported details

Shinyhunters, an extortion group active since 2019 that has run a wide 2026 campaign against companies using Salesforce, listed Questel SAS on its leak site. No independent confirmation from Questel or third-party researchers of the exact intrusion method was found in public reporting.