Ia.Acs.Au Quest Apartment Hotels Data Breach Exposes Nearly 2 Million Customers' Personal Information
Article Content
- •Nearly 2 million customers affected by the Quest data breach.
- •Sensitive data includes credit card numbers with CVVs, passport, and Medicare numbers.
- •The breach was linked to a vulnerability in a third-party service provider.
A significant data breach at Quest Apartment Hotels has compromised the personal information of approximately 1,991,613 customers, including sensitive data such as credit card numbers, passport, and Medicare numbers. The breach was identified on August 19, 2026, following a cyberattack that exploited a vulnerability in a third-party technology provider. The data exposed includes 46,727 credit card numbers with CVVs and 297,739 credit card numbers without CVVs. Quest has confirmed that the affected data primarily relates to records from before June 2025. The company is cooperating with various Australian authorities to address the breach and has begun contacting affected individuals to provide guidance on protective measures. Experts warn that the stolen data could facilitate online fraud and identity theft.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Optus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…