Nearly two million Quest Apartment customers are being urged to contact identity document authorities after a forensic investigation into a major data breach confirmed that passport numbers, driver's licence numbers and credit card details — including CVV numbers — were among the personal information compromised.

The breach, which was first disclosed in August, has now been confirmed to have affected the records of 1,991,613 customers, with the accommodation provider revealing that its earlier assessment had understated the scope of information exposed. Our earlier coverage of the Quest Apartment Hotels data breach and its initial impact on millions of customers outlined the preliminary findings at the time.

What Information Was Compromised in the Quest Data Breach

Quest's original notification to customers indicated that personal data collected before June 2025 had been accessed, including names, email addresses and general contact details. However, the completed forensic analysis has now identified additional categories of sensitive information that were also caught up in the incident.

Among those categories are passport numbers, driver's licence numbers, credit card numbers and CVV numbers. Quest confirmed that 104,268 records contained a passport and/or driver's licence number, though the company stressed that no scanned copies of identity documents were compromised — only the document numbers themselves.

Customers were notified of the updated findings via text message, with the company acknowledging that forensic analysis had identified further categories of information involved in the incident.

Advice for Affected Customers

Emails sent to customers affected by the breach advised them to take precautionary steps with the relevant issuing authorities. Those whose driver's licence number was involved were encouraged to contact their local road authority to discuss obtaining a replacement licence. Customers whose passport number was affected were directed to contact the Australian Passport Office — or the relevant authority for non-Australian passports — to consider whether their document should be flagged or reissued.

Quest subsequently clarified that its official position has always been to recommend customers check with the relevant authorities as a precaution, rather than to mandate document replacement. The company also pointed customers to guidance from the Australian Passport Office, which indicates there is no requirement to replace a passport solely because its number was involved in this breach.

Quest said it is continuing to work with relevant authorities and remains committed to keeping affected customers informed throughout the process.

Quest Operator Issues Apology

The Ascott Limited Australasia, which operates Quest, has responded formally to the escalating situation. Managing director David Mansfield issued a public apology on behalf of the company, acknowledging the distress caused to affected guests.

"For the overwhelming majority of impacted individuals, the information identified at that preliminary stage was limited to a combination of name and contact information," Mansfield said. "Our forensic data analysis has now enabled us to determine the specific types of personal information affected."

"I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected."

What Customers Should Do Now

  • Check whether you have received a text message or email from Quest notifying you of your involvement in the breach.
  • If your driver's licence number was affected, contact your state or territory road authority to discuss your options.
  • If your passport number was affected, reach out to the Australian Passport Office for guidance — noting that replacement is not currently considered mandatory.
  • Monitor your financial accounts for any unusual activity, given that credit card and CVV numbers were among the data exposed.
  • Consider placing alerts or freezes on credit accounts if you have concerns about potential misuse of your information.

The breach originated through a third-party supplier, Quest confirmed, rather than from within its own internal systems directly. Investigations are continuing, and further updates are expected to be communicated to affected customers as they come to hand.