Quest Apartment Hotels’ parent Ascott has published a forensic census that dwarfs the chain’s first August notices. Managing director David Mansfield told customers that information relating to approximately 1,991,613 people was affected after attackers exploited a vulnerability in a third-party service provider and reached a Quest database on 17 August 2026. SBS News reported the September update on the 18th, including a field-by-field inventory that now covers passport and licence numbers, credit cards (some with CVV), vehicle registrations, and small sets of NDIS and Medicare numbers.
This is a verified Quest / Ascott data breach with a company-attested customer count — not a dark-web rumor. Canonical record: https://breachhistory.com/quest-apartment-hotels/quest-apartment-hotels-thirdparty2026. Primary update: SBS. Company page: questapartments.com.au/update.
What happened
Quest first identified an outage on 17 August 2026. Investigation showed a malicious attack through a third-party provider vulnerability, with unauthorized database access. The company said it contained the incident, finished remediation, notified the OAIC and ACSC, and began emailing affected guests. Early public messaging emphasized names, emails, and other contact details for pre-June 2025 records, plus a small date-of-birth set.
The September Ascott update is the census and sensitivity upgrade. Nearly two million customers. Structured counts for high-risk fields. Direct outreach by category so guests know whether they are in the passport bucket, the card-with-CVV bucket, or contact-only.
Timeline
- 17 August 2026: Unauthorized access / site outage identified; containment begins.
- 19–21 August: Public statements and FAQ; OAIC/ACSC notified; early field description is mostly contact data.
- ~18 September 2026: Ascott MD forensic update — ~1,991,613 customers and expanded field inventory reported by SBS.
What data was exposed
Per Mansfield / SBS:
- Approximately 1,991,613 customers overall (records from before June 2025).
- Majority: names and contact details.
- Vehicle registration numbers: 225,300
- Passport and/or driver licence numbers (numbers only; no scanned ID copies): 104,268
- Credit card numbers without CVV (including expired): 297,739
- Credit card numbers with CVV (including expired): 46,727
- Date of birth: 3,328
- NDIS numbers (number only): 271
- Medicare card numbers (number only): 46
That inventory is why this Quest Apartment Hotels data breach matters beyond a marketing-email leak. Passport/DL numbers plus cards with CVV are identity-theft and payment-fraud fuel. Retention of pre-June 2025 records — including expired cards — is the governance question privacy lawyers are already asking in public coverage.
How the attack worked
Quest has not named the third-party vendor or the CVE. Confirmed mechanism language: vulnerability in a third-party service provider’s software enabled malicious database access. Treat it as supply-chain / vendor risk until a post-mortem says otherwise. Guests who booked via Expedia, Wotif, or Booking.com can still be in scope if they stayed at Quest properties and their data sat in the affected database.
Who is at risk
Guests in the ~1.99M set — especially the 104k with ID numbers and 46k with CVV.
Guests with only contact data — still expect phishing that spoofs Quest refunds or “update your stay.”
Staff and partners — vendor access reviews and token rotation.
What Quest and Ascott said
Mansfield apologized and said Quest is contacting people by category with steps and support. Customers should stay alert for suspicious email, SMS, and calls requesting personal or financial information. Official updates live on the Quest site; if you receive no notification, Quest previously said it is unlikely your information was affected — but the September census expansion means late letters may still arrive.
Was I affected?
If you stayed at Quest in Australia, New Zealand, or Fiji before June 2025 and receive a Quest/Ascott notice, follow the category in that letter. If you have not heard anything, check spam for messages from Quest domains and the FAQ on questapartments.com.au before assuming you are clear.
What you should do
- Read the official Quest notice carefully — note whether you are in ID, card, or contact categories.
- If card-with-CVV: cancel/reissue the card and watch statements.
- If passport/DL numbers: watch for identity-fraud applications; consider a credit freeze where available.
- Ignore “Quest breach refund” links; use typed URLs only.
- Enable MFA on email accounts that received Quest confirmations.
- NDIS/Medicare number recipients: contact those agencies’ fraud lines if misuse appears.
- Keep the Quest letter for banks and police if fraud follows.
- Business travellers: tell your company travel desk if a corporate card was used.
- Do not send copies of passports to anyone claiming to “verify” the breach.
- Ask Quest [email protected] which categories apply if your letter is unclear.
Canonical record and sources
Quest Apartment Hotels catalog entry
Evidence-folder note 1 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 2 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 3 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 4 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 5 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 6 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 7 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 8 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 9 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 10 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 11 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 12 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 13 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 14 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 15 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 16 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 17 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 18 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 19 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 20 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 21 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 22 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 23 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 24 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 25 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 26 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 27 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 28 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 29 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 30 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 31 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 32 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 33 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 34 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 35 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 36 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 37 for Quest Apartment Hotels: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.