Security· August 19, 2026 at 02:16 a.m.
Australian Hotel Chain Exposes Customer Data in Third-Party Database Breach
Key takeaways
- Data breach at Quest aparthotel chain
- Personal information of guests exposed
- Third-party database operator involved
An unidentified third-party database operator has led to a data breach at Quest, an Australian aparthotel chain. The incident, which occurred on August 17, 2026, exposed personal information of guests who stayed at the chain before June 2025. The leaked data includes full names and email or contact details, with a small number also involving dates of birth. Quest has contacted all affected guests, secured and fixed the vulnerable systems, initiated forensic investigations, and hired external cybersecurity and privacy advisers. However, the company did not disclose the identity of the third-party service provider, the extent of the data loss, or the number of customers impacted.