Questo, the parent company of Morris Communications, has notified individuals of a data breach after unauthorized access to its network exposed Social Security numbers, financial data, and medical information. Companies that collect and store personal information have a responsibility to protect it with reasonable security measures.
Questo’s Data Breach Investigation
Questo, the parent company of the Georgia-based media conglomerate Morris Communications, has disclosed that it experienced a cybersecurity incident affecting sensitive personal information belonging to a substantial number of individuals. According to a notice filed with the California Attorney General’s Office and a related notification issued to affected individuals, Questo detected unusual activity within its network environment on or around October 9, 2025. The company subsequently engaged cybersecurity professionals to investigate.
That investigation concluded in June 2026 that an unauthorized actor had accessed certain files containing personal information between October 1 and October 9, 2025. Questo began formally notifying affected individuals in mid-July 2026, several months after the intrusion was confirmed. As is common in breaches of this scale, the gap between the initial detection of suspicious activity and the completion of a forensic review, followed by legally required notification, reflects the multi-step process companies typically undertake: identifying the scope of unauthorized access, determining which specific individuals and data elements were involved, and preparing notices that comply with a patchwork of state breach-notification laws.
The exposed information reported in connection with this incident is broad, spanning identity documents, financial account details, and medical records. When a single breach exposes this range of data types together, the risk to affected individuals is elevated well beyond a typical single-category exposure. Names paired with Social Security numbers and dates of birth create the foundation for full identity theft, while driver’s license and passport numbers add government-issued identification that can be used to pass verification checks with financial institutions or government agencies. The presence of payment card and financial account information raises the possibility of direct financial fraud, and the inclusion of medical information means some individuals may also face the more specific harms associated with healthcare-related identity theft, including fraudulent insurance claims filed in their name.
Media and publishing companies like Morris Communications, along with their parent organizations, often maintain large repositories of employee, subscriber, and business-partner records accumulated over years of operation, which can make them attractive targets for cybercriminals seeking bulk personal data. Questo has not publicly detailed the specific technical vector used in the intrusion, and it remains unclear whether the incident involved ransomware, a compromised credential, or another method of unauthorized access. Individuals affected by this breach should treat any notice they receive from Questo as time-sensitive and take the steps outlined in that notice seriously, since the combination of data types involved here creates meaningful exposure to identity theft, tax fraud, and account takeover.
When Did This Breach Occur?
Questo has stated that the unauthorized access to its systems occurred between October 1, 2025 and October 9, 2025, with the company first detecting unusual network activity on the later date. Following a months-long investigation with outside cybersecurity professionals, Questo determined in June 2026 that files containing personal information had been accessed during that window. The company began sending notification letters to affected individuals on July 17, 2026, roughly nine months after the incident itself occurred.
What Information Was Breached?
Based on Questo’s notification, the information involved in this breach may include full names, dates of birth, Social Security numbers, driver’s license and government-issued identification numbers, passport numbers, financial account information, payment card information, medical information, tax information, and addresses. Not every affected individual necessarily had every category of information exposed; the specific data involved may vary from person to person depending on the records accessed.
What You Can Do
If you received a notice from Questo about this data breach, read it carefully and keep it for your records, as it may reference specific services or deadlines. Consider placing a fraud alert or credit freeze with the three major credit bureaus, Equifax, Experian, and TransUnion, to make it harder for anyone to open new credit in your name. Enroll in any free credit monitoring or identity protection services Questo offers. Regularly review your bank and credit card statements, medical billing summaries, and IRS transcripts for unfamiliar activity, since the range of data exposed here could enable several different types of fraud. Report any suspicious account activity to your financial institutions immediately.
File a Data Breach Lawsuit Against Questo
Companies that collect and store sensitive personal and financial information have a legal obligation to protect it with reasonable security measures. When a breach like this one exposes Social Security numbers, financial account details, and medical records, affected individuals may have grounds to pursue legal action against the company responsible for safeguarding that data.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.