Quest Apartment Hotels Investigating Customer Data Breach Tied to Third-Party Provider
Personal details of Quest guests, including names, email addresses and some dates of birth, were exposed after criminals broke into a database through a flaw in an outside supplier's system.

Key points
- Quest Apartment Hotels confirmed on 17 August 2026 that unauthorised access to a customer database had occurred.
- Exposed data includes full names, email addresses, contact details and, for a smaller group, dates of birth.
- Compromised records all pre-date June 2025 and the breach was traced to a vulnerability in a third-party service provider's system.
- Quest's parent company, The Ascott Limited, has notified Australia's Office of the Australian Information Commissioner and the Australian Cyber Security Centre.
Quest Apartment Hotels, a chain owned by Singapore-based hospitality group The Ascott Limited, told customers this week that criminals had accessed a database holding their personal information. Discovery came on Monday, 17 August 2026.
ABC News Australia first reported the customer email, which confirmed that access came through a security weakness inside an unnamed supplier's system. A flaw in a vendor Quest relied on gave attackers their way in.
What information was taken?
Exposed records include full names, email addresses and contact details. A smaller subset also contains dates of birth. Every compromised entry relates to a booking or interaction recorded before June 2025.
Quest hasn't disclosed how many customers are affected. Threat Vectr contacted Quest and The Ascott Limited for that figure; neither had responded by publication time.
How did the attackers get in?
The entry point was a supplier, not Quest's own core systems. That pattern has appeared repeatedly in recent weeks: our 21 August story on SickKids Hospital's third-party breach traced the same route through a vendor's software flaw. Supplier networks frequently carry weaker controls than the primary company, making them attractive targets for reaching customer data sitting behind them.
Quest says the incident has been contained and affected systems are now secured.
Should affected customers be worried?
Yes, in a limited but practical sense. Names, email addresses and dates of birth are enough to craft convincing phishing messages: fake emails designed to trick recipients into handing over passwords or payment details.
Quest warned customers not to click unexpected links or open attachments, even if a message appears to come from the hotel chain. That's sound advice. If you stayed at a Quest or Ascott-branded property before June 2025, treat any unexpected contact claiming to be from Quest with extra caution. Change passwords only where a site shares the same credentials as your Quest account.
What is Quest doing about it?
The company reported the breach to Australia's privacy watchdog and to the government body that handles national cyber incidents. David Mansfield, managing director for Australasia at The Ascott Limited, signed the customer email and said the company would follow up if its investigation uncovered further relevant details.
No ransomware group has publicly claimed responsibility, and Quest hasn't characterised this as a ransomware attack. At this stage it reads as a data-theft operation through a third-party access point. The scale remains unknown, and that number, when it comes, will determine how seriously regulators treat it.



