The Questo and Morris Communications 2025 data breach involved unauthorized access to the network of Questo Inc., parent company of Morris Communications Company, from October 1 through October 9, 2025. An investigation with outside cybersecurity professionals confirmed access to certain files. A manual review concluded June 22, 2026, that personal information may have been affected.
State notifications report 354 Texas residents, 27 Vermont residents, and 15 Massachusetts residents, establishing a verifiable nationwide lower bound of 396 people. Possible fields were full names, dates of birth, driver's licenses or other government IDs, passports, tax information, SSNs, financial accounts, payment cards, and medical information.
How Was the Questo and Morris Breach Confirmed?
The primary source is Questo recipient-letter filing 2026-1180 in the Massachusetts public archive. It directly confirms the corporate relationship, October 1–9 access period, June 22 review result, unauthorized file access, 24-month Kroll protection offer, and the assistance line at 844-958-8901.
A source-linked summary compiling California, Texas, Vermont, and Massachusetts regulatory records provides the data categories and published state populations. Morris Communications's official incident page is also listed as a notification channel. The sources align on the parent company, incident period, and file access.
What Happened From October 1 Through October 9, 2025?
After detecting unusual activity in its network environment, Questo secured the network and opened an investigation with outside specialists. The comprehensive review found that an unauthorized actor accessed certain files. A manual review determined that some personal information may have been subject to unauthorized access between October 1 and October 9.
The public documents do not disclose the initial-entry method, account or vulnerability used, actor identity, malware, or a ransom demand. File access is confirmed, but the sources provide no evidence of public release, sale, or an open leak. LeakData does not add an unsupported attribution or technical cause.
What Identity and Tax Information Was Affected?
Identity fields included full names, dates of birth, driver's-license or other government-identification card numbers, passport numbers, tax information, and Social security numbers. This combination creates substantial risks of fraudulent account opening, tax-return fraud, government-ID impersonation, and highly credible targeted messages.
The sources do not say every person had every field involved; the person-specific section of a recipient's letter defines the actual scope. “Tax information” does not prove that a taxpayer ID, return, and income details were all present together. LeakData preserves the published top-level category and does not add undocumented subfields.
What Risks Come From Financial and Medical Information?
Financial-account and payment-card information raise transaction-fraud and institution-impersonation risks. Medical information can support fake provider, billing, or insurance messages tied to a person's healthcare relationship. The sources do not separately confirm a bank PIN, card CVV, portal password, diagnosis, or prescription.
A recipient should review financial transactions, new payees, and contact-detail changes and, if health data was involved, benefit statements and unfamiliar provider records. A financial or medical top-level category does not establish exposure of every possible subfield. Protective steps should be matched to the list in the personal notice.
How Many People Were Affected and How Did the Company Respond?
Texas reported 354 people, Vermont 27, and Massachusetts 15. The combined 396 covers only these published state records and is not an exact nationwide total. pwnCount and totalRecords are therefore null, while affectedCountStatus is lower_bound and affectedCountLowerBound is 396. LeakData imported no raw person records.
Questo secured its network, investigated with outside specialists, and said it reviewed information-security practices and internal controls and implemented additional measures. Eligible people received 24 months of complimentary Kroll single-bureau credit monitoring, fraud consultation, and identity-theft restoration. The line is available weekdays from 9 a.m. to 6:30 p.m. Eastern Time.
What Should Affected People Do?
If an SSN, tax field, or government ID was involved, consider freezes at all three credit bureaus, a fraud alert, and an IRS IP PIN. Monitor for passport or license misuse, and discuss account security with the bank or card issuer if financial information was involved. Report unfamiliar transactions promptly through an official channel.
Criminals may use the Morris or Questo name, a real address, or an affected field in fake protection-enrollment, payment, or document-update messages. Independently open the company's and financial institution's official channels instead of following an inbound link. Do not disclose a password, full SSN, card security code, or one-time code.