Back to Home
Gadgets

Australian hotel chain leaks guests’ PII after breach at third-party database operator

Unknown parties know where you stayed last summer, down under, across 120 Quest properties

t
tech4you AI
August 19, 20261 min read
Share

cyber-crime

Australian hotel chain leaks guests’ PII after breach at third-party database operator

Unknown parties know where you stayed last summer, down under, across 120 Quest properties

Australian aparthotel chain Quest has revealed it leaked customer data.

A Reg reader kindly shared an email from the chain with the subject line “Important Security Update Regarding Your Quest Data.”

That missive opens with unwelcome news that “I am writing to inform you of a recent data security incident involving some of your personal information.”

“On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident,” the email continues. “The incident arose from a vulnerability through our third-party service provider.”

Exposed data “relates to records from before June 2025” and includes guests’ full name, plus what Quest described as “Your email and/or other contact details.”

The Register asked the company for comment, and it told us “A small number of data entries also involve Date of Birth.”

Which means whoever accessed this info is now in a decent position to attempt identity fraud.

Quest did not, however, identify the third-party that was the source of the breach, how the breach happened, or the number of customers impacted by the leak.

The company also ignored our question about the extent of the lost data. Quest started operating more than 30 years ago, so we’re keen to know how far back this leak goes.

Quest operates over 120 properties, most in Australia, plus some in New Zealand and Fiji. The Register has found listings for Quest properties on popular third-party travel booking sites such as Expedia, Wotif, and Booking.com – suggesting overseas visitors who stayed in the company’s properties may also be at risk.

The accommodation outfit told The Register it has contacted all affected guests, contained and fixed the leaky systems, completed remediation, commenced forensic investigations, and hired external cyber security and privacy advisers.

This is a developing story and The Register will update it as more information becomes available. ®


Originally published on The Register

Related Articles

Australian hotel chain leaks guests’ PII after breach at third-party database operator | tech4you