Questo Data Breach Exposes Personal Information of Individuals

Other Commercial data breach illustration
Breach Discovery: June 2026Breach Notification: July 2026

What Happened in the Questo Data Breach?

Questo, Inc., the parent company of Morris Communications Company, LLC, has begun notifying individuals about a data security incident that exposed personal information. The company discovered that an unauthorized actor gained access to files stored on its network. As a result, sensitive personal data may have been viewed or taken without permission.

According to the notification, the unauthorized access occurred between October 2025 and October 2025, specifically within the first nine days of that month. Questo did not confirm the exact intrusion method used by the attacker. However, the company stated that it acted quickly once it became aware of suspicious activity on its systems.

Questo determined on June 22, 2026, that personal information had likely been affected. This means several months passed between the intrusion and the confirmation that data had been compromised. The company brought in outside cybersecurity professionals to investigate the incident thoroughly. Investigators conducted a manual review of the affected files to identify exactly which types of information had been exposed.

Because this review process took considerable time, the notification to affected individuals came well after the original intrusion. This gap is common in breach investigations, since companies often need months to fully understand the scope of an attack. In this case, Questo says it secured its network immediately upon discovering the issue, then worked to determine the full impact before notifying anyone.

Who was affected?

The notification letter is addressed to individuals whose personal information Questo maintained, though the company has not publicly disclosed a specific number of affected people. Given that Questo is the parent company of Morris Communications, those affected could include current or former employees, customers, or other individuals whose data was stored within Morris Communications’ systems.

Questo has not clarified whether the breach affected people nationwide or in a more limited geographic area. Similarly, the notification does not specify whether minors were among those impacted, although the enrollment process for identity monitoring services explicitly excludes individuals under 18. Anyone who receives a notification letter from Questo should assume their information was part of the exposed data set.

What Information Was Potentially Exposed?

Questo’s notification letter references specific data elements that were part of the breach, though the general public version of the letter does not spell out every category by name. Based on the structure of the notification and the protective measures offered, the exposed information likely includes several categories commonly involved in similar incidents.

  • Full name
  • Personal identifying information tied to individual records
  • Information that could support identity monitoring enrollment, suggesting sensitive identifiers were involved
  • Potentially financial account details, given the recommendation to monitor financial statements
  • Potentially information relevant to medical privacy, given the inclusion of guidance on protecting medical information

When personal identifiers are exposed, criminals can use them to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can be difficult to detect right away, especially if the victim does not regularly check their credit reports. As a result, affected individuals could face financial harm long after the breach itself occurred.

In addition, if any financial or medical information was included, the risks expand further. Medical identity theft, for example, can lead to inaccurate health records or fraudulent insurance claims. Because these consequences can take time to surface, ongoing vigilance is essential for anyone who received a notification letter.

What is the company doing?

Once Questo learned of the incident, it moved to secure its network right away. The company then launched a formal investigation, working with outside cybersecurity experts to understand what had happened. This investigation included a detailed, manual review of the files that may have been affected, which is why the process took several months to complete.

In response to the breach, Questo has arranged identity monitoring services through Kroll at no cost to affected individuals. These services include credit monitoring, fraud consultation, and identity theft restoration support. Additionally, Questo set up a dedicated toll-free response line so affected individuals can ask questions and receive guidance from staff familiar with the incident.

What Should Affected Individuals Do?

Enroll in the Free Identity Monitoring Services

Anyone who received a notification letter should take advantage of the complimentary identity monitoring services Questo has arranged through Kroll. This service includes credit monitoring, fraud consultation, and identity restoration assistance if fraud does occur. Enrollment must happen within 90 days of the date on the letter, so acting quickly matters.

To sign up, visit the Kroll enrollment website listed in the notification letter and use the membership number provided. Because this service is free, there is little downside to enrolling right away. This monitoring can help catch suspicious activity early, before it turns into a larger financial problem.

Place a Fraud Alert or Security Freeze

Because personal information was involved, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires creditors to verify your identity before opening any new accounts in your name. This step is free and can be requested through any one of the three major credit bureaus.

For even stronger protection, consider placing a security freeze on your credit file. A security freeze blocks lenders from accessing your credit report entirely unless you lift it first. This means identity thieves generally cannot open new accounts using your information while the freeze remains active.

Monitor Financial Accounts and Credit Reports

Beyond enrolling in monitoring services, affected individuals should regularly review their own bank and credit card statements. Look for any charges or new accounts that you do not recognize. Because fraud can sometimes take months to appear, this habit should continue well beyond the free monitoring period.

You can also request a free credit report from each of the three major credit bureaus once per year. Reviewing these reports allows you to spot unfamiliar accounts or inquiries that could indicate identity theft. If you notice anything suspicious, report it to the credit bureau and consider contacting a data breach attorney for guidance.

Stay Alert for Phishing Attempts

After a data breach, scammers often try to exploit the situation by sending fake emails or text messages pretending to be from the breached company. Therefore, affected individuals should be cautious about unexpected messages asking for personal information or login credentials. Always verify the sender before clicking any links or providing details.

If you receive a suspicious message referencing this breach, do not respond directly. Instead, contact Questo through the official response line listed in your notification letter to confirm whether the message is legitimate. This simple step can prevent a second wave of fraud stemming from the original breach.

Protect Your Medical Information

If your medical information was part of the exposed data, it is worth reviewing your health insurance statements for unfamiliar claims or services. Medical identity theft can result in inaccurate records that affect future treatment decisions. Because of this, catching errors early is important for both your finances and your health.

Consider requesting a copy of your medical records from your healthcare providers to check for inconsistencies. If you spot anything unusual, report it to your insurance provider and healthcare provider right away. Acting promptly can help limit the damage caused by medical identity theft.



More Information

Official data breach notification from California Attorney General

Related Data Breaches