Questo Data Breach Exposed SSNs and Financial Data; Notification Delayed 9 Months
The city exploration platform faced a critical security failure, leaving sensitive user data exposed for nearly three quarters of a year.
Questo Inc., a global platform for city exploration games and scavenger hunts, has fallen victim to a significant data breach that exposed the most sensitive personal information of its users. The incident has sparked immediate concern over identity theft risks and the company's delayed response in notifying those affected.
Unauthorized actors accessed the company's systems between October 1 and October 9, 2025. The breach compromised highly sensitive data, including Social Security numbers, government-issued identification such as passports and driver's licenses, and financial account information. The exposure affected residents across multiple states, including California, Texas, Massachusetts, and Vermont.
A Critical Timeline Gap
While the intrusion occurred in early October 2025, the company did not report the incident to the California Attorney General until July 16, 2026. This timeline reveals a gap of approximately nine months between the initial unauthorized access and the official reporting and notification phase. The internal review of the breach was reportedly not completed until June 22, 2026, suggesting a prolonged period of uncertainty regarding the scope of the leak.
Industry Implications
This failure is particularly severe given the nature of the stolen data. Unlike email addresses or passwords, Social Security numbers and government IDs are permanent identifiers that cannot be easily changed, significantly increasing the long-term risk of identity theft for Questo users. In the tech industry, a nine-month delay in notification is widely viewed as a critical failure in incident response. Such delays often lead to increased legal liability and severe regulatory penalties under state and federal data protection laws, as users are left unable to freeze their credit or monitor their accounts in a timely manner.
What's Next
As the scale of the exposure becomes clear, the company faces potential legal challenges. Various legal firms are investigating the incident for potential class action lawsuits, with a primary focus on the company's adherence to mandatory breach notification laws. Users are advised to monitor their financial statements and consider credit freezes given the sensitivity of the compromised government identifiers.