Quest Group Listed by Anubis Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Quest Group was listed by the Anubis ransomware group on 18 September 2026, with the group claiming to hold data belonging to an undisclosed number of people. Individuals are advised to watch for unusual account activity and to verify any direct contact from the organisation.
On September 18, 2026, the ransomware group known as Anubis listed Quest Group on its public leak site. The listing is an unverified claim by the group. Quest Group has not publicly confirmed the claim as of writing, and independent confirmation from regulators or established breach indexes is not part of the available record.
What the listing asserts, in brief, is that employee data, internal files, and other materials the group describes as unexpected discoveries are involved. How many people might be affected is unknown, and the types of data are not set out in detail beyond that summary. For anyone connected to Quest Group as staff, a partner, or a customer, the practical question is what a leak-site claim does and does not establish—and what to do if personal information later proves to have been involved.
Inside the listing
According to the Anubis listing, Quest Group appears among organisations the group says it has targeted. The reported date associated with the listing is September 18, 2026. The public summary attached to the claim refers to employee data, internal files, and a few unexpected discoveries. It does not publish a verified headcount of affected people, a full inventory of file categories, a technical account of how access was supposedly obtained, or a claimed timeline of intrusion and exfiltration.
Scale, method, and precise contents remain undisclosed in the material provided. Leak-site posts are a form of pressure: groups name a victim and describe holdings in order to push for payment before any promised publication. That marketing language is not the same as a forensic inventory. Until Quest Group or another authoritative source speaks on the record, the listing should be read as an allegation, not as settled fact about what left whose systems.
Inside Anubis
Anubis is known in public reporting as a ransomware and extortion operation that uses leak sites as part of a double-extortion model: encrypt or disrupt systems where it can, and threaten to publish stolen data if a ransom is not paid. Like other groups in this category, it typically advertises victims on a dedicated site, sometimes with sample files or descriptive blurbs meant to demonstrate access. Public coverage of Anubis has associated it with opportunistic targeting across sectors rather than a single industry niche, and with the familiar cycle of countdown-style pressure and staged releases when negotiations stall.
None of that general pattern proves what happened in any one case. For this listing, the only incident-specific assertions on record are those the group itself has posted: that Quest Group is named, that the claim was reported on the date above, and that the blurb points to employee-related material, internal files, and unspecified further finds. Claims beyond that—about tools used, dwell time, or exact datasets—are not included in the facts available here and should not be inferred.
Who is Quest Group?
Quest Group is a named commercial organisation. Public detail in this record does not expand on its full legal structure, geography, or line of business beyond the name used on the listing. In general terms, firms operating under group structures often hold human-resources records, internal operational documents, contracts, and correspondence that support day-to-day work with employees, suppliers, and clients.
A leak-site claim against such an organisation matters because workplace and internal files can touch identities, contact details, and business relationships far beyond a single office. Consequence does not require accepting the attackers’ story as proven; it follows from the simple fact that people rely on employers and counterparties to handle personal and commercial information carefully, and any credible allegation prompts sensible caution until clarity arrives.
What data was at risk
The listing does not disclose a confirmed catalogue of exposed data types. The attackers’ own summary mentions employee data, internal files, and a few unexpected discoveries. That phrasing is their description, not an audited inventory. Exact contents remain unconfirmed, and no figure for people affected is given.
If files were taken from an organisation of this kind, firms in comparable positions typically hold some mix of the following—stated here only as sector-typical holdings, not as proof of what Anubis obtained:
- Employee identity and contact information, role details, and HR administration records
- Internal memoranda, project files, and operational documents
- Vendor, contractor, or client correspondence and related commercial paperwork
- Credentials or access-related material sometimes stored alongside internal systems documentation
- Other business records whose sensitivity depends on context and retention practice
Without confirmation from Quest Group or a regulator, it is not possible to say which of these, if any, were involved. Readers should treat “unexpected discoveries” as unspecific attacker language rather than a defined data class.
The real-world impact
If the claim were accurate and employee or internal material had left the organisation, affected individuals could face routine but serious risks: phishing that references real workplace details, attempts to reset accounts using known email addresses, and social engineering aimed at colleagues or family. Internal files can also expose commercial relationships, making partner organisations targets for follow-on fraud even when they were not the named victim.
For the organisation, a public extortion listing can mean reputational pressure, distraction of leadership, legal and notification questions under applicable privacy rules, and cost—whether or not every claim on the leak site is later borne out. For the wider public, the listing illustrates how ransomware crews use naming and vague data descriptions to create urgency. It does not, by itself, establish negligence, technical failure, or the true scope of any intrusion. Those conclusions would require investigation and disclosure that are not in the present record.
People affected numbers are unknown. That uncertainty cuts both ways: it avoids false precision, and it means individuals cannot rule themselves in or out from the listing text alone. Conditional vigilance is the proportionate response.
If your data was involved
If you believe your information may have been tied to Quest Group—as an employee, former staff member, or partner—act on the possibility rather than on panic. Prefer official channels from the company if it issues guidance. Treat unexpected messages that cite the incident as suspicious until verified. Consider monitoring financial and important online accounts for unusual activity, and refresh passwords on work-related and personal email, especially where reuse was a habit. Enable multi-factor authentication where it is available. If you are notified by Quest Group or a regulator, follow those instructions, including any offer of credit or identity monitoring.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets elsewhere. A scan does not prove or disprove this particular Anubis claim; it only helps you see whether your email is already circulating in compiled breach material and whether further hardening is overdue. Until Quest Group confirms or denies the listing, keep assumptions provisional and focus on steps that reduce harm if personal data was involved.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Better Accounting Solutions Listed by Anubis Ransomware GroupGellibrand Support Services Listed by Anubis Ransomware GroupMarlborough Partners Listed by Anubis Ransomware GroupCaduceus Medical Group Listed by Anubis Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Quest Group Listed by Anubis Ransomware Group →
Publicly posted by anubis — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.