Australian Hotel Chain Quest Leaks Guest PII via Third-Party Breach
Quest, an Australian hotel chain, has disclosed a data breach exposing guest personal information due to a vulnerability at a third-party database operator.

The Australian aparthotel chain Quest has confirmed a significant data breach that has exposed the personal information of its guests. The incident, which came to light on August 17, 2026, originated from a vulnerability exploited at a third-party service provider that manages Quest's databases.
According to an email sent to affected customers, the unauthorized access to the database system was identified and contained by Quest on August 17. The compromised data pertains to guest records from before June 2025. The exposed information includes guests' full names, email addresses, and other contact details. In a subset of these records, dates of birth were also compromised, significantly increasing the risk of identity fraud for those affected.
Quest has not publicly identified the third-party vendor responsible for the breach, nor has it disclosed the total number of customers impacted or the specific technical details of how the vulnerability was exploited. Given Quest's 30-year history and its operation of over 120 properties primarily in Australia, with additional locations in New Zealand and Fiji, the potential scope of the breach could be extensive, possibly affecting international visitors who booked through third-party travel sites like Expedia or Booking.com.
The hotel chain stated that it has taken immediate steps to address the incident. This includes containing and fixing the compromised systems, completing remediation efforts, and engaging external cybersecurity and privacy advisors to conduct a thorough forensic investigation. Quest has also confirmed that it has contacted all guests whose data was affected by the breach.
While Quest has assured customers that the immediate vulnerability has been addressed, the full extent of the compromise and the potential downstream impacts remain under investigation. The incident highlights the persistent risks associated with third-party vendor security, where a single point of failure can lead to widespread data exposure for numerous customers.
This breach underscores the critical importance of robust security practices not only for direct service providers but also for their entire supply chain. Organizations relying on third-party data processors must ensure stringent security audits and contractual obligations are in place to mitigate the risk of such incidents. The ongoing investigation by Quest and its cybersecurity advisors will be crucial in understanding the full ramifications and preventing future occurrences.