Quest Apartment Hotels confirms customer data breach linked to third-party vulnerability
Quest Apartment Hotels confirms customer data breach linked to third-party vulnerability
Quest Apartment Hotels has confirmed a data breach involving customer information after unauthorised access was detected in a database system, with the incident traced to a vulnerability involving a third-party service provider.
The accommodation group identified the unauthorised access on 17 August 2026 and moved to contain the incident and secure affected systems. Quest has since said the breach has been contained and remediation work completed.
The compromised information relates to customer records dating from before June 2025 and primarily includes names, email addresses and other contact details. Quest has also confirmed that a small number of records contained dates of birth.
Reports indicate other contact information, including street addresses, was among the information compromised in some records. At this stage, there has been no public indication in the sources reviewed that customer payment card details or passwords were exposed.
Quest has contacted customers it has identified as potentially affected and said it will continue notifying individuals if its ongoing investigation uncovers additional impacts.
“If you do not receive a notification from us, it is unlikely that your personal information has been affected,” the company said in an update reported by Australian media.
The company has notified the Office of the Australian Information Commissioner (OAIC) and Australian Cyber Security Centre (ACSC), and has engaged external cybersecurity and privacy advisers as it investigates the incident.
David Mansfield, Managing Director for Australasia at Quest parent company The Ascott Limited, apologised to customers over the breach and said protecting customer privacy and security remained a priority.
Quest has also warned customers to be alert to unexpected emails, phone calls and text messages, particularly communications requesting personal information or payment, or encouraging recipients to click links or open attachments.
The exposure of names and contact information creates a particular risk of phishing and social engineering, where attackers can use legitimate personal information to make fraudulent communications appear more convincing.
Customers receiving communications purporting to be from Quest should therefore independently verify requests rather than relying on contact details or links contained in unsolicited messages.
The incident also places renewed attention on third-party cybersecurity risk. Quest’s privacy policy states that the company uses third-party information system providers that may store or have access to customers’ personal information.
While Quest has attributed the incident to a vulnerability involving a third-party service provider, the provider involved has not been publicly identified in the reports reviewed.
The breach illustrates how an organisation’s cyber exposure can extend beyond systems it directly operates. Hotels and accommodation providers can maintain significant volumes of personal information associated with bookings, loyalty programs and customer communications, making both their own infrastructure and connected service providers potential targets.
Quest operates an extensive network of apartment hotels, with its Australian website listing more than 120 locations.
The company said it is continuing to assess the incident for further security improvements and will work with the third-party provider to ensure required remediation is carried out.
The investigation remains ongoing, meaning the full number of affected customers and complete scope of the compromised information have not yet been publicly disclosed.
For affected customers, the immediate risk may not necessarily be direct account compromise but the potential secondary use of exposed information. Names, email addresses, contact details and dates of birth can provide useful material for targeted phishing, impersonation and other social-engineering attempts.
Quest has said it will contact customers if its investigation identifies further information relevant to them or additional steps they need to take.