In brief
- Quest Apartment Hotels says the information of nearly two millions customers was compromised in a data breach.
- The data includes credit card, passport, and Medicare numbers.
Personal information of nearly two million Quest Apartment Hotels customers has been compromised in a data breach, including credit card, passport and Medicare numbers.
Last month, the accommodation provider identified a cyberattack on a database system via a vulnerability in a third-party technology provider.
David Mansfield, the managing director of The Ascott Limited, which owns Quest Apartment Hotels, provided an update this week, saying a forensic data analysis revealed information relating to approximately 1,991,613 customers was affected.
The majority of information related to names and contacts, but also included:
- Vehicle registration numbers: 225,300
- Passport and/or driver licence numbers (the number only; no scanned copies of ID documents were affected): 104,268
- Credit card numbers (no CVV, including expired credit cards): 297,739
- Credit card numbers (with CVV, including expired credit cards): 46,727
- Date of birth: 3,328
- NDIS number (the number only; no scanned copies of cards or documents were affected): 271
- Medicare card number (the number only; no scanned copies of cards or documents were affected): 46
News that makes sense
Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.
All the information relates to records from before June 2025.
Mansfield said the company was contacting those affected directly to inform them of which category they were in, the steps they could take, and available support.
"I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected," he said.
Quest said it first identified an outage on its website on 17 August, with investigation revealing "a malicious attack" had exploited a vulnerability in a third-party service provider's software.
The company is advising customers to remain alert for suspicious emails, text messages and telephone calls, particularly communications requesting personal, financial or account information.
Quest said it was cooperating with the Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre and Victoria Police.
Last year's Annual Cyber Threat Report warned cyberattacks were a growing problem in Australia, with financial losses, ransomware attack frequency, and the number of reported data breaches all increasing.
After a major data breach involving millions of Optus customers in 2022, the federal government overhauled privacy laws, requiring companies to destroy or actively de-identify personal information as soon as it was no longer needed.
Incident raises data concerns
Paul Watters, chief executive of Cyberstronomy, which provides cyber risk expertise, said all businesses needed to have a clear understanding of the personal data they hold and why.
"Often, this is not the case," he told SBS News.
"Quest says all of the affected information came from records dating from before June 2025. That immediately raises a governance question: for each category of information, why was it still being retained?"
He said the incident could serve as a lesson for organisations.
"Audit your data holdings. Know what you have, where it is, why you are retaining it, how long you need it, and when it should be deleted or de-identified. Data you no longer hold cannot be stolen in a breach," he said.
Belinda Barnet, a Swinburne University data privacy expert, told SBS News the latest incident raised concerns about the type of data some companies were still retaining.
"Companies like Quest don't need to retain your passport after you've actually identified yourself," she said.
"We really need to have more public discussion about how [companies are] going to destroy information that's no longer needed."
For the latest from SBS News, download our app and subscribe to our newsletter.

