HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Questo, Inc.
bd_a5c6ff979e16a9d8 · schema v1 · pii pii-v1
Full breach record for Questo, Inc. →Questo, Inc. detected unusual network activity on October 9, 2025. An investigation revealed unauthorized access to certain files between October 1 and October 9, 2025. The company secured its network and engaged outside cybersecurity professionals. Identity monitoring services were provided via Kroll. The incident affected residents in multiple states, including California and Rhode Island.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626601
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 16, 2026
- Raw hash
- 5603aeaeeaccd7a77819a06ba3d333c9ffcbf39b798299a084097a5d75965b2f
Reporting entity
- Name
- Questo, Inc.norm: questo
Victim entity
- Name
- Questo, Inc.norm: questo
Incident
- Discovered
- Oct 9, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unknown
- Threat actor
- External
Compliance
- Time to disclose
- 40 weeks(280 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.