Australia
A Third-Party Vulnerability, Not Quest’s Own Systems
On 17 August 2026, Quest Apartment Hotels — one of Australia’s largest serviced-apartment operators, trading for roughly 35 years across more than 160 properties in Australia, New Zealand and Fiji — identified unauthorised access to a database system, tracing the entry point to a vulnerability in a third-party service provider rather than its own infrastructure. Its initial disclosure described the exposure as “primarily names, email addresses, and/or other contact details.”
That initial picture didn’t hold. A mid-September update, following completed forensic analysis, confirmed the incident affected approximately 1,991,613 customers — and that the exposed data included 297,739 credit card numbers (46,727 with CVV), 104,268 passport and/or driver’s licence numbers, 225,300 vehicle registration numbers, and a small number of Medicare and NDIS numbers. All records predate June 2025.
Between the 17 August disclosure and the mid-September revision, the scope of “what was taken” grew by roughly 500,000 records and added three entirely new categories of exposed data — CVVs, passports and Medicare numbers — none of which featured in the first public account.
Source: Cyber Daily, Information Age, SBS News, Insurance Business magazine — August–September 2026