Australian hotel chain leaks guests’ PII after breach at third-party database operator
Unknown parties know where you stayed last summer, down under, across 120 Quest properties
Australian hotel chain Quest has disclosed a data breach that leaked sensitive customer information. In an email titled "Important Security Update Regarding Your Quest Data," the company informed customers that their personal details were compromised due to unauthorized access to a database system. The incident occurred on August 17, 2026, and resulted from a vulnerability in a third-party service provider.
The leaked data includes guests' full names, along with their email and/or other contact details. The Register inquired about the breach, and Quest responded that a small number of data entries also contained Date of Birth information. However, the company did not specify the third-party responsible for the breach, the method used, or the number of affected customers. Quest's response was vague regarding the extent of the lost data.
Quest, which has been operating for over 30 years, manages more than 120 properties across Australia, New Zealand, and Fiji. The company has been found on popular third-party travel booking sites like Expedia, Wotif, and Booking.com, indicating that international visitors staying in their properties might also be at risk. Quest stated that it has contacted all affected guests, contained and fixed the leaky systems, completed remediation, initiated forensic investigations, and hired external cyber security and privacy advisers. This developing story will be updated as more information becomes available.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.