Quest Apartment Hotels disclosed that unauthorised access through a vulnerability at an unnamed third-party service provider exposed personal data belonging to approximately 1,991,613 customers. The affected database contained records dating from before June 2025 and included contact details, dates of birth, passport and driver's-licence numbers, vehicle registrations, Medicare and NDIS numbers, and payment data; 46,727 records included card numbers and CVV values.
Quest identified the incident on 17 August, notified Australian authorities, and advised affected customers to protect or replace compromised payment cards, consider replacing driver licences, and flag or reissue passports where appropriate. The company also warned of phishing emails and WhatsApp messages impersonating Quest. Australia's Department of Foreign Affairs and Trade said exposure of an Australian passport number does not allow an attacker to obtain a replacement passport, and affected passports remain valid for travel.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Quest Apartment Hotels identified unauthorized access to a database through a vulnerability at an unnamed third-party service provider and began an investigation with external cybersecurity experts. The affected records dated from before June 2025.
Australia's Department of Foreign Affairs and Trade said a compromised Australian passport number cannot be used to obtain a replacement passport. It stated that passports affected by the Quest breach remain safe for international travel and are protected by controls including facial recognition.
Quest advised customers with exposed driver's-licence information to consider obtaining a replacement licence and those with exposed passport numbers to contact the relevant passport authority about flagging or reissuing their passport. It also advised customers to take action regarding affected payment cards.
Quest warned that customers had received unsolicited phishing emails and WhatsApp messages impersonating the company and requesting booking confirmation through a link. It advised recipients not to click links or call phone numbers in those messages.
Quest notified the Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre and Victoria Police. The agencies began assisting the investigation and assessing the impact on affected people.
A subsequent forensic analysis found that the breach affected information for 1,991,613 customers, including passport and driver's-licence details, payment-card data, vehicle registrations, dates of birth, NDIS numbers and Medicare numbers. Quest reported 46,727 card numbers with CVVs and 297,739 card numbers without CVVs among the exposed records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.