Questo, Inc. Data Breach Exposes Sensitive Personal Information of Hundreds
Shamis & Gentile P.A., a class action law firm specializing in data breach cases, is investigating a cybersecurity incident involving Questo, Inc., a Georgia-based market research firm. The breach, discovered on October 9, 2025, exposed sensitive personally identifiable information (PII) of affected individuals.
About Questo, Inc.
Founded in 2012 and headquartered in Augusta, Georgia, Questo provides software and data services to businesses in the federal contracting sector. Its offerings include federal contract opportunities and market profiles for government agencies and vendors.
The Breach
Questo detected unusual activity within its network on October 9, 2025, prompting an investigation with external cybersecurity experts. The probe revealed that an unauthorized actor accessed files containing personal data between October 1 and October 9, 2025.
Exposed Information
The compromised data includes:
- Full names and dates of birth
- Government-issued IDs (driver’s licenses, passport numbers)
- Social Security numbers
- Tax and financial account information
- Payment card details
- Medical information
Impact
At least 354 Texas residents and 15 Massachusetts residents have been confirmed as affected. Legal representatives are reviewing potential compensation claims for those impacted by the breach.
Source: https://www.claimdepot.com/investigations/questo-data-breach-2026
Questo cybersecurity rating report: https://www.rankiteo.com/company/questo
"id": "QUE1784645219",
"linkid": "questo",
"type": "Breach",
"date": "10/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'At least 354 Texas residents '
'and 15 Massachusetts residents',
'industry': 'Federal Contracting, Software and Data '
'Services',
'location': 'Augusta, Georgia, USA',
'name': 'Questo, Inc.',
'type': 'Market Research Firm'}],
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Full names',
'Dates of birth',
'Government-issued IDs (driver’s '
'licenses, passport numbers)',
'Social Security numbers',
'Tax and financial account '
'information',
'Payment card details',
'Medical information']},
'date_detected': '2025-10-09',
'description': 'Questo, Inc., a Georgia-based market research firm, '
'experienced a data breach that exposed sensitive personally '
'identifiable information (PII) of affected individuals. The '
'breach was discovered on October 9, 2025, after unusual '
'activity was detected within its network. The unauthorized '
'actor accessed files containing personal data between October '
'1 and October 9, 2025.',
'impact': {'data_compromised': 'Sensitive personally identifiable information '
'(PII)',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential compensation claims',
'payment_information_risk': 'High'},
'investigation_status': 'Ongoing',
'references': [{'source': 'Shamis & Gentile P.A.'}],
'regulatory_compliance': {'legal_actions': 'Potential compensation claims '
'under review'},
'response': {'third_party_assistance': 'External cybersecurity experts'},
'threat_actor': 'Unauthorized actor',
'title': 'Questo, Inc. Data Breach Exposes Sensitive Personal Information of '
'Hundreds',
'type': 'Data Breach'}