SKIP TO MAIN CONTENT

Nearly two million Quest Apartment Hotels customers affected by data breach

Experts say the incident raises fresh questions about how long companies are retaining customer data for.

The side of a hotel building which has signs saying "Quest" on it.
Quest Apartment Hotels said information about nearly two million customers was involved in the breach. Source: AAP / James Ross

4 min read

Published

By Miles Proust

Source: SBS News


Skip to article content

In brief

  • Quest Apartment Hotels says the information of nearly two millions customers was compromised in a data breach.
  • The data includes credit card, passport, and Medicare numbers.

Personal information of nearly two million Quest Apartment Hotels customers has been compromised in a data breach, including credit card, passport and Medicare numbers.

Last month, the accommodation provider identified a cyberattack on a database system via a vulnerability in a third-party technology provider.

David Mansfield, the managing director of The Ascott Limited, which owns Quest Apartment Hotels, provided an update this week, saying a forensic data analysis revealed information relating to approximately 1,991,613 customers was affected.

The majority of information related to names and contacts, but also included:

  • Vehicle registration numbers: 225,300
  • Passport and/or driver licence numbers (the number only; no scanned copies of ID documents were affected): 104,268
  • Credit card numbers (no CVV, including expired credit cards): 297,739
  • Credit card numbers (with CVV, including expired credit cards): 46,727
  • Date of birth: 3,328
  • NDIS number (the number only; no scanned copies of cards or documents were affected): 271
  • Medicare card number (the number only; no scanned copies of cards or documents were affected): 46

News that makes sense

Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

All the information relates to records from before June 2025.

Mansfield said the company was contacting those affected directly to inform them of which category they were in, the steps they could take, and available support.

"I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected," he said.

Quest said it first identified an outage on its website on 17 August, with investigation revealing "a malicious attack" had exploited a vulnerability in a third-party service provider's software.

The company is advising customers to remain alert for suspicious emails, text messages and telephone calls, particularly communications requesting personal, financial or account information.

Quest said it was cooperating with the Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre and Victoria Police.

Last year's Annual Cyber Threat Report warned cyberattacks were a growing problem in Australia, with financial losses, ransomware attack frequency, and the number of reported data breaches all increasing.

After a major data breach involving millions of Optus customers in 2022, the federal government overhauled privacy laws, requiring companies to destroy or actively de-identify personal information as soon as it was no longer needed.

Incident raises data concerns

Paul Watters, chief executive of Cyberstronomy, which provides cyber risk expertise, said all businesses needed to have a clear understanding of the personal data they hold and why.

"Often, this is not the case," he told SBS News.

"Quest says all of the affected information came from records dating from before June 2025. That immediately raises a governance question: for each category of information, why was it still being retained?"

He said the incident could serve as a lesson for organisations.

"Audit your data holdings. Know what you have, where it is, why you are retaining it, how long you need it, and when it should be deleted or de-identified. Data you no longer hold cannot be stolen in a breach," he said.

Belinda Barnet, a Swinburne University data privacy expert, told SBS News the latest incident raised concerns about the type of data some companies were still retaining.

"Companies like Quest don't need to retain your passport after you've actually identified yourself," she said.

"We really need to have more public discussion about how [companies are] going to destroy information that's no longer needed."


For the latest from SBS News, download our app and subscribe to our newsletter.


Get SBS News straight to your inbox

Sign up now for daily news from Australia and around the world. You can also subscribe to Insight's weekly newsletter for in-depth features and first-person stories.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Follow SBS News

Download our apps

Listen to our podcasts

Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS

SBS World News

Take a global view with Australia's most comprehensive world news service

Stream now

Watch the latest news videos from Australia and across the world