Questo, Inc.
ent_5d4862915a2822f654dd2a76
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
11,950
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Questo, Inc.
- Normalized
- questo— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- New Hampshire State AGas victim2026-07-23
Questo, Inc. notified the NH Attorney General of unauthorized access to its network affecting approximately 7 New Hampshire residents. The incident occurred between October 1 and October 9, 2025, and was discovered on October 9, 2025. Affected data includes full names, Social Security numbers, and financial account numbers. Questo contained the incident, engaged outside cybersecurity professionals, and is providing complimentary identity monitoring through Kroll to affected individuals.
- Vermont State AGas victim2026-07-22
Questo, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-22. The reporting organization type is Other Commercial. 27 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
- Massachusetts State AGas victim2026-07-17
Questo, Inc. disclosed a security incident occurring between October 1 and October 9, 2025, where an unauthorized actor accessed files containing personal information. The breach was detected and reported on June 22, 2026. Questo engaged outside cybersecurity professionals, secured its network, and is offering 24 months of identity monitoring via Kroll to affected individuals. No evidence of identity theft was found.
- Texas State AGas victim2026-07-17
Questo, Inc. based in Augusta, Georgia, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-22 and reported on 2026-07-17. 354 Texas residents were affected. 11,950 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information. Consumers were notified via Notice by publication in print media;Posted at company website or special website;U.S. Mail;Email.
- California State AGas victim2026-07-16
Questo, Inc. detected unusual network activity on October 9, 2025. An investigation revealed unauthorized access to certain files between October 1 and October 9, 2025. The company secured its network and engaged outside cybersecurity professionals. Identity monitoring services were provided via Kroll. The incident affected residents in multiple states, including California and Rhode Island.
- Nebraska State AGas victim2026-07-15
Questo, Inc. notified affected individuals of a security incident where an unauthorized actor accessed files containing personal information between October 1 and October 9, 2025. Questo detected the activity on October 9, 2025, and confirmed the unauthorized access on June 22, 2026. The company engaged outside cybersecurity professionals and Kroll for identity monitoring services.