Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Quest Hotels data breach: Almost 2m impacted, almost 50k credit cards compromised

The hotel chain’s managing director has confirmed that the August data breach impacted 1.9 million customers: “I sincerely apologise to those who have been affected.”

Tue, 22 Sep 2026
Quest Hotels data breach: Almost 2m impacted, almost 50k credit cards compromised

Quest Hotels has shared more details of the data breach it disclosed last month after it said it had completed its forensic investigation into the incident in an update published last week.

“As we previously advised, we identified unauthorised access to a database system arising from a vulnerability through a third-party technology provider. We immediately took steps to contain the incident and secure the affected system,” the hotel’s managing director, David Mansfield, said in a 16 September update.

“We have now completed a forensic data analysis into the incident. We have confirmed that information relating to approximately 1,991,613 customers was affected. All the information identified relates to records from before June 2025.”

 
 

Details of the incident were originally disclosed on 19 August, but Quest has now been able to confirm the nature of the data compromised in the breach, which includes an undisclosed number of complete credit card details, including CVV numbers.

A total of 46,727 credit cards and their CVVs were impacted, although the hotel notes that the number includes expired cards. Most of the compromised data was “just” names, addresses, phone numbers, and email addresses; however, apart from credit details, other types of personal data exposed by the breach include:

  • 225,300 vehicle registration numbers
  • 104,268 passport or driver’s license numbers (not scanned documents, just numbers)
  • 297,739 credit numbers without CVVs (including some expired cards)
  • 3,328 dates of birth
  • 271 NDIS numbers
  • And 46 Medicare numbers (again, numbers only, not scanned cards).

“Not every type of information listed above was affected for every individual,” Quest said.

“We are contacting impacted individuals directly to advise them of the specific categories of personal information relating to them that was affected, as well as the practical steps they can take in response, and the support available.”

In response to the incident, Quest said its priority has been containment and informing those affected, alongside understanding how the breach occurred. The Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre, and Victoria Police have all been informed.

“We have worked with external legal counsel and forensic data analysis specialists throughout our investigation and have strengthened our security controls,” Quest said.

“We have also engaged with our third-party technology provider to remediate the affected environment and implement additional security measures.”

Mansfield said Quest does not take this incident “lightly” and that the hotel appreciated customers’ patience.

“We are sorry this incident occurred and for the concern it has caused,” Mansfield said.

“We remain focused on supporting affected individuals and on continuing our review of the measures used to protect information entrusted to us.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: