ShinyHunters Lists Questel, Alcon, and Lumenis on Leak Site With New Extortion Claims

ShinyHunters has added Questel, Alcon, and Lumenis to its leak site, alleging the theft of Salesforce records and internal corporate data.
Graphic showing the ShinyHunters logo above panels for Questel, Alcon, and Lumenis, each labeled “Pay or Leak,” illustrating the group’s alleged extortion claims against the three organizations.
ShinyHunters has allegedly added Questel, Alcon, and Lumenis to its leak site, claiming to have stolen Salesforce records and internal corporate data. The claims remain unconfirmed.

The ShinyHunters extortion group has added three organizations to its data leak site, alleging separate data theft incidents affecting Questel SAS, Alcon Inc., and Lumenis Ltd. The claims surfaced on August 1, 2026.

According to the listings, the group claims to have stolen Salesforce data and internal corporate files from each organization. None of the three companies had issued any public statement regarding the alleged incidents at the time of publication.

Three organizations newly listed

ShinyHunters claims the following data was obtained from each organization:

  • Questel SAS: More than 21 million Salesforce records containing some personally identifiable information (PII), along with approximately 147 GB of internal corporate data.
  • Alcon Inc.: More than 25 million Salesforce records containing some PII.
  • Lumenis Ltd.: More than 1.1 million records containing some customer and employee PII, along with more than 176 GB of internal corporate data.

Each listing includes what the group describes as a final warning, giving the organizations until August 4, 2026, to make contact before the allegedly stolen data is published.

Salesforce data appears to be a common theme

Two of the three listings specifically reference Salesforce records, continuing a pattern seen in several recent ShinyHunters claims involving cloud-hosted business platforms. The alleged theft of Salesforce data could potentially expose customer, employee, partner, or sales information depending on how each organization’s environment was configured.

For Questel and Lumenis, the group also claims to have obtained large volumes of internal corporate files totaling more than 147 GB and 176 GB, respectively. However, the listings do not provide a detailed breakdown of the contents beyond those high-level claims.

Claims remain unconfirmed

ShinyHunters has previously claimed responsibility for numerous high-profile data extortion incidents, but publication on a leak site alone does not confirm that an intrusion occurred or validate the scope of the data allegedly obtained.

If confirmed, the alleged breaches could expose customer, employee, and corporate information across three organizations operating in different industries. BreachNews will update this article if Questel, Alcon, or Lumenis issue public statements or additional evidence regarding the alleged incidents becomes available. Readers can also monitor active ransomware and data extortion activity using the BreachNews Ransomwatch tracker, which tracks newly listed victims across major leak sites.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site