Australian apartment hotel chain Quest has warned customers that their personal information may have been compromised after hackers gained unauthorised access to a database through an external service provider, in a breach detected on Monday, August 17.
The company — which operates more than 160 properties across Australasia, including over 120 in Australia — said it moved immediately to contain the incident after identifying the unauthorised access and has launched a forensic investigation to determine the full extent of the breach.
What Information Was Exposed in the Quest Data Breach
It is understood the breach exposed the personal details of approximately 1.7 million guests, including full names, email addresses and/or other contact details. The affected records relate to bookings made before June 2025.
A smaller subset of customers has been more seriously affected. Up to 1,700 guests had their dates of birth exposed in addition to other personal information, Quest confirmed.
"A small number of data entries also involve date of birth," the company said in an email to affected customers.
Quest described the source of the vulnerability as originating from a third-party service provider, stating: "The incident arose from a vulnerability through our third party service provider." The company said its forensic investigation is ongoing to establish precisely what data was accessed and by whom. Incidents of this nature form part of a broader global pattern of security hacking incidents affecting organisations across multiple industries.
Quest's Response and Advice to Affected Customers
Quest said it has already contacted customers it has identified as potentially affected, and will continue to notify others if further impact is uncovered through its investigation.
"If you do not receive a notification from us, it is unlikely that your personal information has been affected," the company told customers.
In the meantime, Quest is urging all customers to remain vigilant for suspicious communications, including unexpected phone calls, text messages or emails — particularly any that request confirmation of personal details, ask recipients to click links, or seek payment. These are common indicators of phishing attempts that frequently follow data breaches.
Customer Reaction and Broader Context
The breach has generated significant discussion online, with a number of Quest customers sharing their experiences after receiving notification emails from the company. Some reported receiving alerts in connection with multiple client bookings made during the affected period, while others said notifications arrived overnight or during Wednesday morning.
With more than 120 properties operating across Australia alone, Quest is one of the country's most prominent apartment hotel chains, meaning the potential reach of the breach is considerable. The company's investigation is continuing, and further notifications to customers remain possible as more information comes to light.
Guests who believe they may have been affected but have not yet received a notification are advised to monitor their email and remain cautious about any unsolicited contact requesting personal or financial information.

