Quest Apartment Hotels Investigating Customer Data Breach Tied to Third-Party Provider
Personal details of Quest guests, including names, email addresses and some dates of birth, were exposed after criminals broke into a database through a flaw in an outside supplier's system.

Key points
- Quest Apartment Hotels confirmed on 17 August 2026 that unauthorised access to a customer database had occurred.
- Exposed data includes full names, email addresses, contact details and, for a smaller group, dates of birth.
- The breach affected records created before June 2025 and was traced to a vulnerability in a third-party service provider's system.
- Quest's parent company, The Ascott Limited, has notified Australia's Office of the Australian Information Commissioner and the Australian Cyber Security Centre.
Quest Apartment Hotels, a hotel chain owned by Singapore-based hospitality group The Ascott Limited, told customers this week that criminals had accessed a database holding their personal information. The breach was discovered on Monday, 17 August 2026.
The company sent an email to affected guests, first seen by ABC News Australia, confirming that the unauthorised access came through "a vulnerability", meaning a security weakness, inside a system run by an unnamed third-party service provider. In plain terms: a supplier that Quest used for its operations had a flaw that gave attackers a way in.
What information was taken?
Exposed records include full names, email addresses and other contact details. Quest says a smaller subset of records also contains customers' dates of birth. All compromised data relates to bookings or interactions recorded before June 2025.
The company has not disclosed how many customers are affected. Threat Vectr has contacted Quest and The Ascott Limited for that figure; neither had responded at time of publication.
How did the attackers get in?
The entry point was a third party, not Quest's own core systems. That is a common pattern. Criminals probe supplier networks, which often carry weaker security controls than the main company, to reach the customer data sitting behind them.
Quest says the incident has been contained and the affected systems are now secured.
Should affected customers be worried?
Yes, in a limited but practical sense. Names, email addresses and dates of birth are enough for criminals to craft convincing phishing messages, where fraudsters send fake emails designed to trick people into handing over passwords or payment details.
Quest itself warned customers not to click unexpected links or open attachments, even if a message appears to come from the hotel chain. That is sound advice.
If you stayed at a Quest, Citadines or Oakwood property (all Ascott brands operating in Australia and globally) before June 2025, treat any email or text claiming to be from Quest with extra caution right now. You do not need to change passwords unless a site you use shares the same password as your Quest account; in that case, update it.
What is Quest doing about it?
The company has reported the breach to the Office of the Australian Information Commissioner, Australia's privacy watchdog, and to the Australian Cyber Security Centre, the government body that handles national cyber incidents. David Mansfield, managing director for Australasia at The Ascott Limited, signed the customer email and said the company would follow up if the investigation uncovered further relevant details.
No ransomware group has publicly claimed responsibility for this incident, and Quest has not characterised it as a ransomware attack. It reads, at this stage, as a data-theft operation through a third-party access point.


