The Ascott Limited and Quest Apartment Hotels: Quest Apartment Hotels customers' personal data exposed in security breach

The Ascott Limited and Quest Apartment Hotels: Quest Apartment Hotels customers' personal data exposed in security breach

Quest Apartment Hotels Investigates Data Breach Impacting Customer Records

Quest Apartment Hotels has confirmed a security breach exposing customers' personal data, including full names, email addresses, and contact details. A limited number of records also contained dates of birth. The incident, detected on 17 August 2026, stemmed from unauthorized access to a database via a vulnerability in a third-party service provider.

The company acted swiftly to contain the breach and secure affected systems, stating the incident has since been resolved. Quest has notified Australia’s Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC). In a customer email, David Mansfield, Managing Director for Australasia at The Ascott Limited (Quest’s parent company), apologized for the breach and assured customers that further updates would be provided if additional risks were identified.

While the exact scale of the breach remains unclear, social media reports indicate affected customers received notifications overnight. Quest operates under The Ascott Limited, which also owns brands like Citadines and Oakwood, with a presence in Australia and globally.

The incident follows Origin Energy’s recent disclosure of a breach affecting 900,000 customers, underscoring ongoing cybersecurity challenges in the region. Quest has advised customers to remain cautious of phishing attempts, particularly unsolicited links or attachments. Further details are pending as the investigation continues.

Source: https://www.abc.net.au/news/2026-08-19/quest-apartment-hotels-data-security-breach/107053574

Ascott Australia cybersecurity rating report: https://www.rankiteo.com/company/ascott-australia

Quest Apartment Hotels cybersecurity rating report: https://www.rankiteo.com/company/quest-apartment-hotels

"id": "ASCQUE1787106872",
"linkid": "ascott-australia, quest-apartment-hotels",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Hospitality',
                        'location': 'Australia',
                        'name': 'Quest Apartment Hotels',
                        'type': 'Hotel/Apartment Rental'}],
 'attack_vector': 'Third-party service provider vulnerability',
 'customer_advisories': 'Customers notified via email; advised to be cautious '
                        'of phishing attempts.',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Full names',
                                              'Email addresses',
                                              'Contact details',
                                              'Dates of birth']},
 'date_detected': '2026-08-17',
 'description': 'Quest Apartment Hotels confirmed a security breach exposing '
                "customers' personal data, including full names, email "
                'addresses, contact details, and a limited number of dates of '
                'birth. The incident stemmed from unauthorized access to a '
                'database via a vulnerability in a third-party service '
                'provider.',
 'impact': {'data_compromised': 'Personal data (full names, email addresses, '
                                'contact details, dates of birth)',
            'identity_theft_risk': 'High',
            'systems_affected': 'Database'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'root_causes': 'Vulnerability in third-party '
                                           'service provider'},
 'recommendations': 'Customers advised to remain cautious of phishing '
                    'attempts, particularly unsolicited links or attachments.',
 'references': [{'source': 'Quest Apartment Hotels Customer Notification'}],
 'regulatory_compliance': {'regulatory_notifications': ['Office of the '
                                                        'Australian '
                                                        'Information '
                                                        'Commissioner (OAIC)',
                                                        'Australian Cyber '
                                                        'Security Centre '
                                                        '(ACSC)']},
 'response': {'communication_strategy': 'Customer email notification, '
                                        'regulatory notifications',
              'containment_measures': 'Secured affected systems',
              'incident_response_plan_activated': 'Yes'},
 'title': 'Quest Apartment Hotels Data Breach',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Vulnerability in third-party service provider'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.