Shinyhunters ransomware claims Questel SAS
Extortion attackers calling themselves Shinyhunters say they broke into Questel, a company that manages patents and trademarks for other businesses.
- Report priority
- High
- Named organization
- Questel SAS
- Group
- Shinyhunters
What is known
The attackers say they pulled millions of records out of Questel's Salesforce customer database and copied over 147GB of internal company files, then used the stolen data as leverage to demand payment.
What to do
If you are a client, patent holder, or employee whose information was handled through Questel's Salesforce system, watch for a breach notice from Questel and treat unexpected emails claiming to be from Questel or referencing this leak with caution until the company confirms what data was taken.
Reported details
Shinyhunters, an extortion group active since 2019 that has run a wide 2026 campaign against companies using Salesforce, listed Questel SAS on its leak site. No independent confirmation from Questel or third-party researchers of the exact intrusion method was found in public reporting.