No firewall rule stops an employee who believes they are talking to IT support. That is the entire story of how Questel SAS ended up on an extortion group’s leak site.
What happened
ShinyHunters listed Questel, a French intellectual property management firm that administers patent and trademark portfolios for corporations and law firms, on its dark web leak site on August 1, alongside eyewear and pharmaceutical companies Alcon and Lumenis, with a contact deadline of August 4. When Questel didn’t pay, the group began publishing data. Nine days after that deadline, on August 13, Questel confirmed the breach was real. The company said a voice phishing, or vishing, call gave the attacker entry to a Sales SharePoint site inside its Microsoft 365 environment. No malware, no zero-day, no credential-stuffing list. One convincing phone call to one employee.
Why the attack vector matters more than the CVE would
ShinyHunters is the same group behind a monthslong campaign abusing Salesforce Experience Cloud OAuth tokens against roughly 400 companies. What Questel shows is that the group hasn’t retired its older playbook, it has simply added M365 vishing as a second track running in parallel. That matters because most enterprise security budgets are weighted toward patching software, not toward training a help desk to recognise a social engineering call, and toward locking down which SharePoint sites a single compromised session can reach. A vulnerability scanner will never flag “an employee who trusts a phone call.”
The part every European company handling client data should sit with
Questel doesn’t sell software or run infrastructure, it manages other companies’ intellectual property. Its customers are corporations and law firms who never had a breach of their own, yet now have Questel notifying them that their patent and trademark filing data may be in an extortion group’s hands. Questel has notified France’s data protection authority, CNIL, filed criminal complaints, and is contacting affected customers. That is the GDPR reality of running any business that holds client data on behalf of others: the breach happens on your infrastructure, but the notification obligations cascade to everyone who trusted you with their information.
What to actually do about this
Voice phishing defence isn’t a product you buy, it’s a process: verified callback numbers for any request touching account access or permissions, a documented identity-verification script for help desk and IT staff, and Conditional Access policies that limit what a single compromised session can reach even after an attacker gets in. If your organisation handles sensitive client data through Microsoft 365 or Salesforce and you haven’t tested whether your staff can be talked past your controls, that gap is worth finding before ShinyHunters or the next group finds it for you.
If you want your help desk procedures, Conditional Access configuration, or SharePoint sharing permissions reviewed against this exact attack pattern, contact Excello Digital. We help European organisations close the gap between a convincing phone call and a leak site listing.
