On December 28, 2025, budgeting and performance-management software provider Questica appeared on the leak site of the qilin ransomware group, which claims to have stolen and is prepared to publish the company’s internal files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Questica
Get alerted the next time Questica files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Questica’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates that Questica was listed on the qilin ransomware leak site with an entry dated December 28, 2025. The group states it exfiltrated internal data during a ransomware attack and is using the leak site to pressure the victim. Exact volume and types of records have not been independently verified, but ransomware operators routinely publish samples of stolen documents, employee information, financial spreadsheets, and operational files. No confirmed count of affected individuals has been released, leaving current and former customers, employees, and partners uncertain about their exposure.
Why This Matters for You and Your Family
When a company that handles budgeting, procurement, or performance data for schools, municipalities, or private organizations is breached, the information stolen can include personal details that reach far beyond the workplace. Employee records, vendor contracts, and client spreadsheets often contain names, addresses, Social Security numbers, banking information, and email addresses. If any of those records relate to you or your family — perhaps through a school district, local government contract, or employer that uses Questica — your data may now sit on a ransomware leak site. Once posted, that information rarely disappears; it spreads across underground forums and can be reused for years.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one company. Stolen internal files frequently contain spreadsheets that link employee names to personal email accounts, phone numbers, spouse names, and children’s school records. These connections allow attackers to build an identity chain that moves from a work breach into personal accounts. A single exposed work email can unlock password-reset links for banking, healthcare, or retail sites. The same files can reveal which family members use the same passwords or share devices, turning one breach into repeated account takeovers. Gaming accounts belonging to children are especially vulnerable because kids often reuse credentials that appear in parent-related documents.