Back to Articles
Quest Apartment Hotels Confirms Data Breach

Information Age

ENRICHED

Details

Date Published
19 Aug 2026
Priority Score
1
Australian
Yes
Created
20 Aug 2026, 06:03 am

Authors (1)

Description

More than 1.5 million records potentially involved.

Summary

The article reports on a significant data breach at Quest Apartment Hotels affecting over 1.5 million records, stemming from a vulnerability in a third-party service provider. While the incident highlights systemic risks in the digital supply chain and data privacy, it does not directly address frontier AI models, autonomous agents, or existential risks. The event is relevant to broader Australian cybersecurity policy and the regulatory oversight provided by the OAIC and ACSC, though it lacks specific focus on AI safety frameworks.

Body

Quest Apartment Hotels confirms data breach More than 1.5 million records potentially involved. By Tom Williams on Aug 19 2026 12:15 PM Print article Quest says customer names, email addresses, and contact details were exposed. Image: Quest Apartment Hotels Customer information has been accessed by hackers through a third-party provider, accommodation chain Quest Apartment Hotels announced on Wednesday. The serviced apartment company is one of the largest in Australia, with more than 120 locations across the country, as well as others in New Zealand and Fiji. "Unauthorised access to a database system" was identified on Monday following "a vulnerability through a third-party service provider", Quest said in a statement. "We immediately took steps to contain the incident and secure the affected systems," the company said. "The incident has been contained, and remediation work has been completed." Personal information exposed Information exposed in the breach included records from before June 2025, Quest said, and "primarily involves names, email addresses, and/or other contact details" such as street addresses, but no financial information. "A small number of data entries also involve date of birth," the company said. Information Age understands more than 1.5 million records were potentially involved, but very few included dates of birth. Quest would not name the third-party service provider when contacted for comment, but said it was following appropriate measures to notify government regulators and inform affected customers. "We have contacted those we have identified as potentially affected to notify them and provide support, and we will continue to do so if our investigation identifies any further impact," the company said. "If you do not receive a notification from us, it is unlikely that your personal information has been affected." Quest said it had engaged external cybersecurity and privacy experts, and its forensic analysis is ongoing. "The security of our guests’, staff and partners’ information remains our absolute priority," it said. Quest says it has notified federal information and cybersecurity officials of its third-party data breach. Image: Shutterstock Customers told to 'be cautious' of potential scams In an email to affected customers seen by Information Age, the Australasia managing director of Quest's Singaporean parent company The Ascott Limited, David Mansfield, told affected customers to "remain vigilant" to potential scams. “Be cautious of unexpected calls, texts or emails, particularly anything asking you to confirm personal information, click a link or make a payment,” he said. “Don’t click unexpected links or open attachments: This applies even if a message appears to come from Quest, your bank or another organisation you trust.” “... Check before responding: If you receive a communication claiming to be from Quest and are unsure whether it is genuine, please contact us directly using our official contact details." Mansfield said Quest and its parent company had notified the Office of the Australian Information Commissioner (OAIC), the Australian Cyber Security Centre (ACSC), and "other relevant authorities as required" about the data breach. "We are continuing to assess the incident to identify any further improvements we can make on our systems going forward," he said. “We will work with our third-party service provider to ensure that any improvements required on their systems are appropriately remediated. “... We are very sorry this has happened and for any concern it may cause. “Protecting the privacy and security of our customers is extremely important to us." The announcement of Quest's third-party breach comes after other recent data breach notifications from the likes of Origin Energy, GP network Partnered Health, and Lifeline. Editor's note 20/08/26: This article was updated to include quotes from The Ascott Limited's email to affected Quest customers. Tom Williams Tom Williams is a senior journalist at Information Age with key interests in consumer technology, artificial intelligence, quantum computing, cybersecurity, and telecommunications. He was previously a digital journalist at ABC News, where he covered technology and breaking news. You can follow Tom on Bluesky, LinkedIn, or Threads, contact him at [email protected], and send tip-offs via secure email to [email protected]. Tags: quest data breach cybersecurity