Quest Apartment Hotels has disclosed that personal data belonging to its guests has been compromised via a security incident involving one of its third-party service providers.
“On Monday, 17 August 2026, we identified unauthorised access to a database system arising from a vulnerability through a third-party service provider. We immediately took steps to contain the incident and secure the affected systems,” Quest said in an update on its website and in correspondence sent to impacted guests.
The hotel chain added that the incident had been contained and remediation work completed.
“We have undertaken forensic analysis to establish what information was accessed and the extent of the incident,” Quest said.
“Our investigation so far has confirmed that the information involved relates to records from before June 2025 and primarily involves names, email addresses, and/or other contact details. A small number of data entries also involve Date of Birth.”
Given that Quest has operated for around 35 years and has more than 160 locations across Australia, New Zealand, and Fiji, the amount of data compromised could be sizeable. Quest has not disclosed how many of its guests have been contacted.
Quest added that it has engaged external privacy and cyber security advisors.
“The security of our guests', staff and partners' information remains our absolute priority,” Quest said.
“We are continuing to work with relevant privacy and cyber security authorities as our investigation progresses.”
No threat actor has claimed responsibility for the incident as of the time of writing.
Kash Sharma, Managing Director APAC at cyber security firm BlueVoyant, said the breach of such a trusted brand “hit home for a lot of Australians”.
“Hospitality providers hold significant volumes of personally identifiable information (PII) on their guests, including full names, contact details and in some cases dates of birth, and unlike a password, PII can't be reset once it's exposed,” Sharma told Cyber Daily.
“The immediate risk for affected customers isn't the breached data on its own, it's what attackers do with it next. Names, contact details, and dates of birth are the raw ingredients for convincing phishing and identity fraud, including fake emails that look like they come from Quest itself. Customers should treat any unexpected message about bookings, refunds or account verification with suspicion, avoid clicking links or attachments, and go directly to the company through official channels if they need to check anything.”
Sharma said the takeaway for business, however, was the point of entry.
“For businesses, the detail that matters most is that this breach reportedly originated through a vulnerability in a third-party service provider, not Quest's own front door. That's now the defining pattern of Australian breaches across healthcare, telecommunications, energy, and now hospitality: attackers going through the vendor ecosystem, where visibility is weakest,” Sharma said.
“Every organisation holding customer data needs to know, continuously, which suppliers can touch that data and how secure they are, because your customers won't distinguish between your systems and your vendors' when their information ends up exposed."
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.