Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: breach-verification (2 articles)Clear

ShinyHunters leaks Questel data taken through a vishing call into Microsoft 365

The extortion group ShinyHunters published data stolen from Questel, a French intellectual-property software and services firm, after a voice phishing call gave attackers access to a Sales SharePoint site in its Microsoft 365 environment. The group claimed more than 21 million records, but the published corpus verified out to about 1.2 million real email addresses, along with names, employers, job titles, physical addresses, and phone numbers, mostly corporate contacts from sales and marketing. Questel confirmed the unauthorized access but has not endorsed the larger figure. It is the same voice-phishing-into-connected-cloud pattern, and the same inflated-claim behavior, seen in other recent ShinyHunters cases.

Check
Harden identity and help desk processes against voice phishing, since a single tricked employee gave attackers access to a cloud collaboration site, and be skeptical of headline record counts in extortion claims.
Affected
Questel corporate contacts whose names, employers, titles, addresses, and phone numbers were leaked, about 1.2 million email addresses; the detailed business profiles support convincing targeted phishing despite the inflated original claim.
Fix
Adopt phishing-resistant authentication, train staff against vishing, tightly control access to Microsoft 365 sites like SharePoint, monitor for unusual data access, and verify breach claims before treating attacker figures as fact.

ShinyHunters leaks Carhartt data, but half the records were synthetic test data

The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.

Check
Affected Carhartt customers should be alert to targeted phishing and scam calls using their real name, address, and phone number, and treat unexpected messages referencing recent orders with suspicion.
Affected
About 12.9 million Carhartt customers whose emails, names, phone numbers, and physical addresses were leaked; the detailed profiles support convincing phishing, even though millions of the leaked records were synthetic.
Fix
For defenders, verify breach claims before reacting since raw dumps can be inflated with synthetic data, and keep test and benchmark datasets out of production stores that hold real records.