Quest Apartment Hotels Hit by Data Breach as 1.5 Million Records Face Exposure
Synopsis
The serviced-apartment chain detected unauthorised access to a database and moved to contain the incident after a vulnerability in a third-party provider was identified.
Quest Apartment Hotels is continuing its investigations into the data breach as the company announced today that it verified unauthorised access to a database containing more than 1.5 million potentially affected records.
The company confirmed that the breach was discovered by Quest on 17 August 2026, after identifying a vulnerability relating to a third party service provider. This breach impacted information held by Quest prior to June 2025.
Customer information accessed
The information accessed in the data breach of Quest Apartment Hotels includes customers’ names, e-mail addresses, street addresses, and other contact information. Some records also contain birth dates, according to Quest, which did not include financial information.
In addition, the company says that upon detecting unauthorised access, it acted quickly to curb the damage and protect the affected systems. Quest noted that it has resolved the issues and notified affected customers who are likely to be impacted.
Furthermore, the company is conducting a forensic investigation with the assistance of independent cybersecurity and privacy experts to determine the cause of the breach. In addition, Quest has been in contact with pertinent privacy and cybersecurity authorities about the data breach.
The third-party vendor was not publicly identified, and customers should remain vigilant about any unsolicited phone calls, texts, or e-mails requesting personally identifying information, payments, or other sensitive information.
Breach comes amid record Australian notifications
The data breach at the Quest Apartment Hotels comes after Australia tied its highest number of data breach notifications recorded in a single year.
There were 1,205 notifications to the Office of the Australian Information Commissioner (OAIC) in 2025, compared to 1,112 notifications in 2024, an increase of eight per cent. In addition, of the 716 notifications, malicious and criminal attacks were responsible for 716 of them.
Health service organisations had the highest number of data breach notifications, with 225 notifications, followed by financial services with 157 notifications and Australian government agencies with 118 notifications. In addition, there were 103 notifications in relation to business and professional associations.
According to their current corporate website, as of the publication of this article, Quest has serviced apartments in more than 160 locations in Australia, New Zealand, Fiji, and the United Kingdom.
The Ascott Limited owns Quest, which is a division of Singapore-based CapitaLand Investment’s hospitality division. The investigation into the data breach at Quest Apartment Hotels is ongoing, and the company expects to provide more information to customers about additional impacts.
Source: InformationAGE
Pooja Malik is a business journalist with over six years of experience covering startups, entrepreneurship, and emerging trends. She has previously worked with leading media platforms such as YourStory Media and BW BusinessWorld, where she reported on business, policy, and market developments. Currently, she serves as Editor at The Inspirepreneur Magazine, where she writes and edits stories across business, lifestyle, and travel, with a focus on clarity, accuracy, and reader relevance.