Post

Australian Hotel Chain Leaks Guests' PII After Breach

Australian Hotel Chain Leaks Guests' PII After Breach

Australian Hotel Chain Leaks Guests’ PII After Breach

🚨 Important Security Update Regarding Your Quest Data 🚨

Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain informing customers of a recent data security incident involving some of their personal information.

According to the email, “On Monday, 17 August 2026, we identified unauthorized access to a database system and immediately took steps to contain the incident.” The communication further stated, “The incident arose from a vulnerability through our third-party service provider.”

Exposed Data

The exposed data relates to records from before June 2025 and includes guests’ full names, along with what Quest described as “Your email and/or other contact details.” A small number of data entries also involve dates of birth. However, Quest did not identify the third-party source of the breach, how it happened, or the number of customers impacted by the leak.

Company Response

Quest operates over 120 properties, primarily in Australia, with some in New Zealand and Fiji. The Register has found listings for Quest properties on popular third-party travel booking sites such as Expedia, Wotif, and Booking.com, suggesting overseas visitors who stayed in the company’s properties may also be at risk.

The accommodation outfit has contacted all affected guests, contained and fixed the leaky systems, completed remediation, commenced forensic investigations, and hired external cybersecurity and privacy advisers.

This is a developing story, and The Register will update it as more information becomes available.

Read full article

This post is licensed under CC BY 4.0 by the author.