Quest Apartment Hotels confirms breach affecting 1.5 million customer records via third-party vulnerability

The breach was identified on Monday, 17 August 2026, and traced to a vulnerability via a third-party service provider, resulting in unauthorised access to a Quest database.
Quest notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre as part of its regulatory reporting.
The third-party service provider involved in the breach was not named by Quest.
There are indications the breach could affect guests who stayed at Quest properties booked via major external sites, with references to Expedia, Wotif and Booking.com.
Quest sent customers an email titled 'Important Security Update Regarding Your Quest Data' detailing the incident and urging caution with unexpected communications.
Quest Apartment Hotels has confirmed a data breach affecting more than 1.5 million customer records, after hackers gained unauthorised access to a database through a third-party service provider. The breach was detected on 17 August 2026 and exposed names, email addresses, and contact details across Quest's roughly 120 properties in Australia, New Zealand, and Fiji, according to Smart Company and 7News.
Quest said no financial information was compromised. A small number of records also included dates of birth. The company has since contained the breach, notified regulators, and begun alerting affected customers directly by email.
The breach traces back to a vulnerability in an unnamed third-party service provider. Quest has not disclosed which vendor was involved. Hackers used that vulnerability to access a Quest customer database, ACS reported. The incident affected records created before June 2025.
Quest's owner, The Ascott Limited, confirmed the breach and said it would keep customers informed if new details emerged. Quest engaged external cybersecurity and privacy experts to investigate and complete remediation. The company also notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre.
7News reported that around 1.7 million customers may be affected. The exposed data included names, email addresses, and other contact details. A small subset of records also contained dates of birth. No passwords or payment details were accessed.
The breach may reach beyond direct Quest bookings. Guests who booked through external platforms — including Expedia, Wotif, and Booking.com — could also be affected, according to Head Top Topics. This widens the potential pool of people at risk significantly.
Quest sent affected customers an email titled 'Important Security Update Regarding Your Quest Data.' The message urged people to be cautious of unexpected emails, calls, or texts. Customers were advised not to click suspicious links or open unknown attachments.
Security experts warn that exposed names and emails are prime tools for phishing and identity fraud. Affected guests are advised to monitor their accounts for unusual activity. If you think you were a Quest customer before June 2025, treat unexpected messages with extra caution — even if they look legitimate.
Quest leadership said protecting customer privacy is a top priority. The company says it has completed remediation of the breach. External cybersecurity experts remain engaged as the investigation continues, ACS reported.
The Ascott Limited said it would notify customers if any further relevant information came to light. Regulators in Australia are now aware of the incident. The identity of the third-party vendor at the center of the breach remains undisclosed, leaving key questions unanswered about how the vulnerability arose and how long it existed.
Publishers
10
Articles
24
Reach
34