1. Executive summary
On 2 August 2026, the actor "shinyhunters" publicly named Questel SAS (France, questel.com) as a ransomware victim, claiming exfiltration of over 21 million Salesforce records containing PII and 147 GB+ of internal corporate data. The actor issued a final extortion deadline of 4 August 2026, threatening public leak and "digital problems." Attribution to shinyhunters is unconfirmed — the actor has no MITRE ATT&CK profile in verified reference data — and the claim rests on a single source (ransomware.live). EMEA financial services clients should assess exposure to Questel as a third-party data processor and to the Salesforce dataset for downstream credential or identity fraud risk.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | Questel SAS is a named third-party provider (IP/legal services SaaS) whose claimed breach involves 21M+ Salesforce records and 147 GB+ of corporate data — clients using Questel must assess whether this constitutes an ICT third-party incident affecting their own operational resilience. | Clients with Questel in their ICT service provider inventory must evaluate dependency and potential impact on their own services under DORA third-party risk obligations. |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | If a client's data held by Questel (or via Salesforce processing) is confirmed compromised, the incident may meet the classification threshold for a major ICT-related incident requiring authority notification. | Clients must determine whether the Questel breach triggers their own major-incident reporting timeline, distinct from Questel's own obligations. |
No NIS2 or UK NIS article is specifically engaged beyond generic incident-response obligations; the trigger facts do not distinctively invoke supply-chain security measures under NIS2 Art. 21(2)(d) unless Questel is confirmed as a direct supplier to an in-scope essential/important entity.
3. Technical analysis & attack chain
Attribution caveat: "shinyhunters" has no MITRE ATT&CK profile in the verified reference data. Attribution is unconfirmed and single-sourced (ransomware.live). Treat the actor name as a claim, not a confirmed finding.
What is confirmed from the source
- Public naming — shinyhunters posted Questel SAS (questel.com, FR) as a victim on or before 2 August 2026.
- Data claimed exfiltrated: - 21,000,000+ Salesforce records containing "some PII." - 147 GB+ of internal corporate data.
- Extortion mechanism — the actor issued a "final warning" with a deadline of 4 August 2026, threatening to leak the data and cause "several annoying (digital) problems." This is double-extortion: data theft followed by leak threat, not confirmed encryption-based ransomware. No encryption artefact, ransom note, or malware sample is present in the source.
- Victim exposure surface (from ransomware.live enrichment, single-sourced): - Compromised employees: 0 - Compromised users: 10 - Third-party employee credentials: 6 - External attack surface: 12 entries - These figures suggest potential infostealer-derived credential exposure (consistent with Hudson Rock sponsorship context on the page) but no infostealer malware family, C2, or sample is named.
What is NOT confirmed
- Initial access vector — no CVE, exploit, or tooling named.
- Encryption activity — no ransom note, encrypted file extension, or malware payload identified.
- Persistence, C2, lateral movement — no technical detail provided.
- Whether the 21M Salesforce records are Questel's own or include client data from multiple Questel customers.
The term "ransomware" in the source headline reflects the platform's categorisation; the observable facts support data-theft extortion, not necessarily encryption-based ransomware.
4. Mitigation & containment
P1 — within 24 hours
- Identify whether your organisation is a Questel SAS customer or data partner. Check vendor inventory, procurement records, and Salesforce data-sharing or integration configurations.
- If Questel is a current ICT third-party provider: initiate incident assessment under your third-party risk framework. Contact Questel's security or account management for breach confirmation and scope (ask specifically whether your data is in the 21M Salesforce record set or the 147 GB corporate dataset).
- Search Salesforce audit logs and API access logs for anomalous bulk export, report download, or data query activity associated with Questel-integrated objects or connected apps.
P2 — within 72 hours
- If your data is confirmed or likely exposed: activate your ICT-related incident management process. Assess against DORA Art. 19 major-incident classification criteria to determine if authority notification is required.
- Rotate any API keys, OAuth tokens, or service credentials shared with Questel or used in Questel-Salesforce integrations.
- Review the 6 third-party employee credentials flagged in the ransomware.live enrichment — if any belong to your organisation or partners, force password reset and revoke active sessions.
- Notify your DPO / privacy team: 21M+ PII records may trigger GDPR breach notification obligations (72-hour window) if your organisation is a data controller for any subset.
P3 — within 7 days
- If Questel remains a vendor: request a formal post-incident report including root cause, data scope, and remediation timeline. Reassess the contractual provisions against DORA Art. 30 requirements.
- Conduct a retrospective review of Questel's access to your Salesforce tenant — minimise permissions, apply least-privilege to connected apps, and enable Salesforce Shield or equivalent event monitoring if not already in place.
- Update third-party risk register with the incident and any exposure findings.
5. Indicators of compromise
No atomic indicators of compromise (IPs, domains, hashes, file paths) are present in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Bulk Salesforce data export or report download exceeding normal volume | Salesforce audit trail, Salesforce Shield Event Monitoring | Medium — consistent with claimed 21M record exfiltration but not directly observed |
| Anomalous API access to Salesforce objects via third-party connected apps | Salesforce Setup → Connected Apps OAuth Usage, API access logs | Medium |
| Credential reuse from infostealer logs targeting Questel or customer SSO | Identity provider logs, EDR, CASB | Low — inferred from Hudson Rock enrichment context (10 compromised users, 6 third-party credentials); not confirmed as initial access vector |
6. Detection
Insufficient indicators to author detection rules. No malware samples, file artefacts, command-line strings, registry keys, mutex names, or network signatures are present in the source material. Detection should focus on the behavioural indicators in §5 using Salesforce audit logs and identity provider monitoring.
7. Sources
- Ransomware.live — "Victim: Questel SAS – shinyhunters" — https://www.ransomware.live/id/UXVlc3RlbCBTQVMAc2hpbnlodW50ZXJz — Published 2026-08-02
- Ransomware.live enrichment data (compromised users, third-party credentials, external attack surface) — same URL — accessed 2026-08-03
8. Adverse Trace position
This is a credible but single-sourced extortion claim with unconfirmed actor attribution. The data volume claimed (21M+ Salesforce records, 147 GB+ corporate data) is significant, but no malware, encryption evidence, or technical attack-chain detail is available. EMEA financial services clients should treat this as a third-party exposure event, not a direct infrastructure threat, and prioritise determining whether their data flows through Questel or its Salesforce environment. We will monitor for confirmation of the breach by Questel, leak of the dataset after the 4 August deadline, and any emergence of malware samples or technical IOCs. If the dataset is leaked, we will assess it for client credential or PII exposure and issue a follow-up advisory.
Published via PulseTrace — Adverse Trace threat intelligence.