← All articles

ShinyHunters leaks Questel data taken through a vishing call into Microsoft 365

The extortion group ShinyHunters published data stolen from Questel, a French intellectual-property software and services firm, after a voice phishing call gave attackers access to a Sales SharePoint site in its Microsoft 365 environment. The group claimed more than 21 million records, but the published corpus verified out to about 1.2 million real email addresses, along with names, employers, job titles, physical addresses, and phone numbers, mostly corporate contacts from sales and marketing. Questel confirmed the unauthorized access but has not endorsed the larger figure. It is the same voice-phishing-into-connected-cloud pattern, and the same inflated-claim behavior, seen in other recent ShinyHunters cases.

Check
Harden identity and help desk processes against voice phishing, since a single tricked employee gave attackers access to a cloud collaboration site, and be skeptical of headline record counts in extortion claims.
Affected
Questel corporate contacts whose names, employers, titles, addresses, and phone numbers were leaked, about 1.2 million email addresses; the detailed business profiles support convincing targeted phishing despite the inflated original claim.
Fix
Adopt phishing-resistant authentication, train staff against vishing, tightly control access to Microsoft 365 sites like SharePoint, monitor for unusual data access, and verify breach claims before treating attacker figures as fact.