TechNewsReel
Live

ShinyHunters Claims Breach of IP Giant Questel SAS, Threatens 21M Record Leak

The ransomware group claims to have exfiltrated 147GB of corporate data and millions of Salesforce records from the French intellectual property provider.

TechNewsReel Newsroom · August 14, 2026

The ransomware group ShinyHunters has claimed responsibility for a major cyberattack on Questel SAS, a leading French provider of intellectual property services. The breach, announced on August 2, 2026, puts the sensitive data of thousands of global organizations at risk.

According to reports, the attackers claim to have exfiltrated more than 147GB of internal corporate data. Most critically, ShinyHunters asserts they have compromised over 21 million Salesforce records containing personally identifiable information (PII). The group issued a strict ultimatum, threatening to leak the stolen trove if negotiations did not commence by August 4, 2026.

The Role of Questel SAS

Questel SAS operates as a global hub for intellectual property (IP) solutions, specializing in business intelligence and management software for trademarks and patents. The company provides critical infrastructure for legal and innovation professionals, serving approximately 20,000 organizations across 30 different countries. Because of this reach, Questel sits at the intersection of corporate strategy and legal protection for a vast array of international clients.

Implications for Global IP Security

The scale of this breach is particularly concerning given the nature of the data Questel handles. Intellectual property services manage the blueprints of corporate innovation; a leak of this magnitude could potentially expose trade secrets and strategic innovation plans for thousands of corporations and law firms.

Beyond the risk of corporate espionage, the compromise of 21 million PII records creates a significant privacy liability. Such a massive dataset increases the risk of highly targeted phishing attacks against high-value legal and technical targets, who often handle the most sensitive aspects of a company's intellectual assets. When PII is paired with knowledge of specific patent filings or trademark disputes, the potential for social engineering increases exponentially.

What's Next

Industry observers are now waiting to see if Questel SAS will engage with the attackers or if the data will be released on the dark web. While the volume of exfiltrated data has been claimed by ShinyHunters, the full extent of the compromise and the specific types of intellectual property affected remain to be independently verified.

The incident highlights the growing vulnerability of specialized B2B service providers who act as central repositories for sensitive corporate intelligence. As these providers consolidate data for thousands of clients, they become "honey pots" for ransomware groups seeking maximum leverage for extortion. The Questel incident serves as a stark reminder that the security of a corporation's intellectual property is only as strong as the weakest link in its third-party service chain.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.