started · updated
Questel confirms Microsoft 365 breach following vishing attack
French intellectual property services provider Questel has confirmed a breach of its Microsoft 365 environment following a voice phishing (vishing) attack. The company stated that unauthorized access was specifically limited to a Sales SharePoint environment and that its production tools, IP platforms, and SaaS products remained unaffected and fully operational.
Following the breach, the hacking group ShinyHunters claimed to have stolen over 21 million Salesforce records containing personally identifiable information, along with more than 147GB of internal corporate data. Questel has contained the incident and reports no evidence that attackers retain current access to its environment.
Researchers at Zscaler’s ThreatLabz have identified a broader trend where initial access brokers use vishing via Microsoft Teams to target corporate environments. These attacks often begin with spam email flooding to create a sense of technical urgency, followed by attackers posing as IT support to persuade victims to establish remote sessions via tools like Quick Assist. Once access is gained, attackers deploy malware to establish persistence before selling the access to ransomware gangs.
Entities
Microsoft · Questel · ShinyHunters · Zscaler