Quest data leak exposes years of guest records
Australian apart-hotel chain Quest warns guests of a data breach via a third-party provider, risking identity fraud.
Quest, the Australian apart-hotel chain, has warned guests that their personal information may have been exposed in a data breach that originated at a third-party service provider. The company said it detected unauthorized access to a database system on 17 August 2026, and has since been contacting affected customers.
Breach notification and scope
In an email to customers with the subject line "Important Security Update Regarding Your Quest Data," the chain said: "I am writing to inform you of a recent data security incident involving some of your personal information." The message continued: "On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident. The incident arose from a vulnerability through our third-party service provider."
The exposed data "relates to records from before June 2025" and includes guests' full names, plus what Quest described as "Your email and/or other contact details." The Register asked the company for comment, and it told us "A small number of data entries also involve Date of Birth."
Identity fraud risk
The combination of names, contact details, and in some cases birth dates puts affected guests at a heightened risk of identity fraud. Cybercriminals often use such personally identifiable information (PII) to impersonate victims, open fraudulent accounts, or conduct targeted phishing campaigns.
Unanswered questions
Quest did not, however, identify the third-party that was the source of the breach, how the breach happened, or the number of customers impacted by the leak. The company also ignored our question about the extent of the lost data. Quest started operating more than 30 years ago, so we're keen to know how far back this leak goes.
Quest's footprint and global exposure
Quest operates over 120 properties, most in Australia, plus some in New Zealand and Fiji. The Register has found listings for Quest properties on popular third-party travel booking sites such as Expedia, Wotif, and Booking.com – suggesting overseas visitors who stayed in the company's properties may also be at risk.
Response and remediation
The accommodation outfit told The Register it has contacted all affected guests, contained and fixed the leaky systems, completed remediation, commenced forensic investigations, and hired external cyber security and privacy advisers.
Pattern of Australian breaches
This incident adds to a recent string of data breaches in Australia, including the theft of data from six million Qantas customers, a large-scale ransomware breach at MediSecure, and the REvil attack on Medibank. The country's large companies have been under increased scrutiny over their data handling practices.
What guests should do
Affected guests should remain vigilant for suspicious emails, calls, or messages that reference their personal information, and consider changing passwords and monitoring financial statements for unusual activity. They may also wish to contact Quest for further information or to confirm what data was compromised.
Why this matters
This breach highlights the risks posed by third-party service providers, which can become an attack vector for cybercriminals. The fact that Quest has not disclosed the number of affected customers or the identity of the provider leaves guests in the dark about the full extent of the exposure. It also underscores the importance of companies maintaining strict oversight over the security practices of their vendors, especially when handling sensitive personal data.
Sources
- The Register Original source
Continue Reading
When Ransomware Victims Get a Rescue Offer From a Stranger
A ransomware affiliate is contacting victims, offering to delete stolen data for $20,000–$60,000. Experts call it a scam.
Pokémon Center UK Breach Hits Orders
Pokémon Center UK cancels orders after logistics partner CEVA suffers cyberattack, exposing customer data.
French Tax Breach Hits 680K
France's tax agency says 678,000 people had data stolen in a credential-based attack.