Quest Apartment Hotels disclosed a data breach after attackers gained unauthorized access to a database system through a vulnerability at an unnamed third-party service provider. The Australian aparthotel chain said it detected the intrusion on 17 August, contained the incident, and began notifying affected guests by email. Exposed records dated from before June 2025 and primarily included guests’ full names, email addresses, and other contact details, while a smaller subset also contained dates of birth.
Quest said it has fixed the affected systems, completed remediation, launched a forensic investigation, and engaged external cybersecurity and privacy advisers. The company also notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre, but did not disclose the number of affected customers or identify the vendor involved. Guests were warned to be alert for suspicious links or attachments that may appear to come from the hotel chain as the investigation continues.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
After discovering the incident, Quest said it immediately contained the breach, secured the affected systems, and completed remediation. The company also began forensic investigation work and engaged external cybersecurity and privacy advisers.
Quest Apartment Hotels said it identified unauthorized access to a database system on 17 August 2026. The company attributed the intrusion to a vulnerability at an unnamed third-party service provider.
Quest notified affected customers by email during the week of the reports, warning that records from before June 2025 were exposed. The compromised data included names, email addresses or other contact details, and a small number of records also contained dates of birth.
Quest said it notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre about the incident. The references do not specify the exact date of those notifications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.