Skip to content
Quest Apartment Hotels investigates data breach linked to third-party vendor flaw

Quest Apartment Hotels investigates data breach linked to third-party vendor flaw

Teiss • August 19, 2026

Quest Apartment Hotels is investigating a security breach that exposed personal data belonging to customers, with the company notifying those affected in an email this week.

The compromised records predate June 2025 and primarily contain full names, email addresses and other information. A limited number of the affected entries also include customers’ dates of birth.

Quest said it identified unauthorized access to a database system on Monday, Aug. 17, 2026, tracing the intrusion to a vulnerability in a third-party service provider. The company said it acted immediately to contain the breach and secure the systems involved, and that the incident has since been contained.

The company has notified the Office of the Australian Information Commissioner and the Australian Cyber Security Centre, and it is working with outside cybersecurity and privacy advisers as the investigation continues. Quest said it has also completed remediation work following the breach.

David Mansfield, managing director for Australasia at The Ascott Limited, addressed the incident directly with customers. "We are very sorry this has happened and for any concern it may cause. Protecting the privacy and security of our customers is extremely important to us," Mansfield said. "We will you if our investigation identifies any further information that is relevant to you or if there are any additional steps you need to take."

Quest advised customers to avoid clicking on unexpected links or opening attachments, even those appearing to come from the hotel chain. Some customers took to and overnight to confirm they had received the notification email.

In a statement issued Wednesday, Quest said it has already reached out to every customer whose data may have been affected and will notify any additional customers if further impacts come to light during the investigation. The company said customers who do not receive a notification are unlikely to have had their personal information compromised.

Quest operates more than 160 properties across Australia, New Zealand and Fiji, with individual locations run by franchisees under the umbrella of The Ascott Limited, its global parent company. The Ascott Limited also owns other accommodation brands, including Citadines and Oakwood, which operate both in Australia and internationally.

The company has not disclosed the identity of the third-party provider tied to the vulnerability.

Already have an account? Sign in

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF

Extracted Entities