Breaking
Cyber CrimeDeveloping Story

Quest data leak exposes years of guest records

Australian apart-hotel chain Quest warns guests of a data breach via a third-party provider, risking identity fraud.

··1 hour ago·2 min read
pink and silver padlock on black computer keyboard
Photo by FlyD on Unsplash

Quest, the Australian apart-hotel chain, has warned guests that their personal information may have been exposed in a data breach that originated at a third-party service provider. The company said it detected unauthorized access to a database system on 17 August 2026, and has since been contacting affected customers.

Breach notification and scope

In an email to customers with the subject line "Important Security Update Regarding Your Quest Data," the chain said: "I am writing to inform you of a recent data security incident involving some of your personal information." The message continued: "On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident. The incident arose from a vulnerability through our third-party service provider."

The exposed data "relates to records from before June 2025" and includes guests' full names, plus what Quest described as "Your email and/or other contact details." The Register asked the company for comment, and it told us "A small number of data entries also involve Date of Birth."

Identity fraud risk

The combination of names, contact details, and in some cases birth dates puts affected guests at a heightened risk of identity fraud. Cybercriminals often use such personally identifiable information (PII) to impersonate victims, open fraudulent accounts, or conduct targeted phishing campaigns.

Unanswered questions

Quest did not, however, identify the third-party that was the source of the breach, how the breach happened, or the number of customers impacted by the leak. The company also ignored our question about the extent of the lost data. Quest started operating more than 30 years ago, so we're keen to know how far back this leak goes.

Quest's footprint and global exposure

Quest operates over 120 properties, most in Australia, plus some in New Zealand and Fiji. The Register has found listings for Quest properties on popular third-party travel booking sites such as Expedia, Wotif, and Booking.com – suggesting overseas visitors who stayed in the company's properties may also be at risk.

Response and remediation

The accommodation outfit told The Register it has contacted all affected guests, contained and fixed the leaky systems, completed remediation, commenced forensic investigations, and hired external cyber security and privacy advisers.

Pattern of Australian breaches

This incident adds to a recent string of data breaches in Australia, including the theft of data from six million Qantas customers, a large-scale ransomware breach at MediSecure, and the REvil attack on Medibank. The country's large companies have been under increased scrutiny over their data handling practices.

What guests should do

Affected guests should remain vigilant for suspicious emails, calls, or messages that reference their personal information, and consider changing passwords and monitoring financial statements for unusual activity. They may also wish to contact Quest for further information or to confirm what data was compromised.

Why this matters

This breach highlights the risks posed by third-party service providers, which can become an attack vector for cybercriminals. The fact that Quest has not disclosed the number of affected customers or the identity of the provider leaves guests in the dark about the full extent of the exposure. It also underscores the importance of companies maintaining strict oversight over the security practices of their vendors, especially when handling sensitive personal data.

#data breach#quest#australia#pii#third-party

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories