Questo, Inc. data breach — notices going out; personal info including SSNs and medical data may be exposed
If you’ve used Questo (the travel/city-adventure app) and received a data breach notification, here’s what’s been disclosed publicly:
- Questo, Inc. discovered suspicious activity on its network on or about October 9, 2025.
- After investigating, on June 22, 2026 the company determined that files may have been accessed or acquired by an unauthorized third party between October 1–9, 2025.
- The exposed data may include full names, dates of birth, driver’s license/government ID numbers, passport numbers, tax information, Social Security numbers, financial account and payment card information, and medical information.
If you were notified, a few practical steps worth taking:
- Review your account statements and credit reports and watch for suspicious activity.
- Preserve any breach notification letters or emails you received.
- Consider placing a fraud alert and enrolling in credit monitoring.
For context: Edelson Lechtzin LLP, a national class action firm, is investigating a potential class action related to the breach and is offering free case evaluations. Not legal advice, and I’ll note this is attorney advertising — but if you got a notice, it may be worth understanding your options.