2026 Quest Apartment Hotels — third-party DB breach; ~1.99M customers (Ascott forensic update)
Data compromised
Per Ascott MD David Mansfield forensic update (SBS, Sep 18, 2026): information relating to approximately 1,991,613 customers (records pre-June 2025). Majority names/contacts; also vehicle registration numbers 225,300; passport and/or driver licence numbers 104,268 (numbers only); credit card numbers without CVV 297,739; credit card numbers with CVV 46,727 (incl. expired); DOB 3,328; NDIS numbers 271; Medicare card numbers 46.
Technical writeup
Verified Quest/Ascott notices — August 2026, with forensic census update reported September 18, 2026 (SBS citing Ascott MD David Mansfield). Unauthorized access identified 17 August via third-party provider vulnerability; contained and remediated. Forensic analysis: information relating to approximately 1,991,613 customers affected (pre-June 2025 records). Field inventory per Mansfield/SBS: majority names/contacts; vehicle regs 225,300; passport/DL numbers 104,268; cards without CVV 297,739; cards with CVV 46,727; DOB 3,328; NDIS 271; Medicare 46. Company contacting affected by category. Initial Aug notices emphasized names/emails/contacts and small DOB set; September update expands sensitive ID/payment categories. recordsAffected 1991613; companyConfirmed true.
Root cause
Malicious attack exploiting a vulnerability in a third-party service provider’s software; unauthorized database access identified 17 August 2026
References
- https://www.sbs.com.au/news/article/nearly-two-million-quest-apartment-hotels-customers-affected-by-data-breach/6eu396nng
- https://www.questapartments.com.au/update
- https://www.abc.net.au/news/2026-08-19/quest-apartment-hotels-data-security-breach/107053574
- https://newshub.medianet.com.au/2026/08/statement-from-quest-apartment-hotels/167077/
- https://www.theregister.com/cyber-crime/2026/08/19/australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator/5289341