
French intellectual property services provider Questel has confirmed that attackers gained unauthorized access to part of its Microsoft 365 environment following a voice phishing attack, and that some of the stolen data was subsequently published online.
The company disclosed the incident to CyberInsider after we contacted it regarding a ShinyHunters leak site post claiming the theft of more than 21 million records containing some personally identifiable information (PII), along with over 147GB of internal corporate data.
“We are aware of the incident and can confirm that we recently identified unauthorized access to part of our Microsoft 365 environment, specifically a Sales SharePoint environment, following a voice phishing attempt,” Questel told CyberInsider.
Voice phishing, commonly known as vishing, typically involves attackers impersonating trusted personnel over the phone to persuade a target to disclose credentials, approve authentication requests, or otherwise facilitate access to an account.
Questel is a France-based provider of intellectual property software and services, offering patent, trademark, innovation intelligence, and IP management solutions to companies, research organizations, and legal professionals.
According to the company, the unauthorized access has been contained, and there is currently no evidence that the attackers retain access to its environment. Questel also stressed that the incident did not affect its production systems.
“None of our production tools, IP platforms, or SaaS IP products and services have been accessed, and our operations have remained fully operational,” the company said.
ShinyHunters claims 21 million records stolen
The ShinyHunters listing reviewed by CyberInsider names Questel SAS as a victim and claims that “over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data” were compromised.
The listing advertises a downloadable archive exceeding 134GB in compressed form.

However, Questel has not confirmed the attacker's claims in full. While ShinyHunters describes the stolen material as Salesforce records, Questel said the confirmed unauthorized access involved a Sales SharePoint environment in Microsoft 365.
The company did confirm that some data obtained during the incident has been published online.
“We are conducting a detailed forensic review of the published material to determine precisely what information was disclosed and to validate its authenticity and completeness,” Questel said. “We are therefore not in a position to confirm all of the claims made by the threat actor at this stage.”
Questel has not disclosed how the voice phishing attack resulted in access to Microsoft 365, how long the unauthorized access lasted, or what specific categories of customer or corporate information were exposed.
Questel said it has reported the incident to France's data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), and filed criminal complaints with relevant law enforcement agencies.
The company is also contacting affected customers and working with external cybersecurity experts as its investigation continues.







Leave a Reply