Quest Apartment Hotels: Quest breach included thousands of credit card CVVs

Quest Apartment Hotels: Quest breach included thousands of credit card CVVs

Quest Apartment Hotels Data Breach Exposes Nearly 2 Million Customers, Including Sensitive Financial and Identification Details

A significant data breach at Quest Apartment Hotels has compromised the personal information of 1,991,613 customers, far exceeding initial estimates. The incident, first disclosed on 19 August 2024, was later revealed to include passport numbers, driver’s licence details, and credit card information some with CVV codes affecting hundreds of thousands of individuals.

Scope of the Breach

The breach exposed a range of sensitive data:

  • 104,268 customers had passport and/or driver’s licence numbers compromised.
  • 225,300 vehicle registration numbers were also accessed.
  • 46,727 credit card numbers, including CVVs, were stolen posing an immediate fraud risk.
  • An additional 297,739 credit cards (without CVVs) were exposed, some of which were expired.
  • 271 individuals had NDIS numbers leaked, while 46 had Medicare card details exposed.

The breach originated from a third-party software vulnerability, exploited by an unknown threat actor on 17 August 2024, leading to a website outage. Quest’s forensic analysis confirmed that all exposed data predated June 2025.

Potential Risks and Expert Concerns

Cybersecurity experts warn that the combination of credit card details (with CVVs), names, and addresses enables immediate online fraud. While passport numbers alone cannot be used to obtain new documents, they can be leveraged in phishing scams when combined with other stolen data.

Despite the severity, no data leaks have been found on the dark web, and no threat actor has claimed responsibility. The lack of a public extortion demand suggests the breach may have been used for payment fraud, identity theft, or intelligence gathering by state actors.

Quest’s Response

Quest has cooperated with Australian authorities, including the Office of the Australian Information Commissioner (OAIC), Australian Signals Directorate (ASD), Australian Cyber Security Centre (ACSC), and Victoria Police. The company has begun notifying affected customers and implementing cybersecurity improvements to prevent future incidents.

Managing Director David Mansfield issued an apology, acknowledging the breach’s impact and thanking customers for their patience during the investigation. The Department of Foreign Affairs and Trade (DFAT) confirmed that affected passports remain valid for travel, though vigilance against scams is advised.

Source: https://ia.acs.org.au/article/2026/quest-breach-included-thousands-of-credit-card-cvvs.html

Quest Apartment Hotels cybersecurity rating report: https://www.rankiteo.com/company/quest-apartment-hotels

"id": "QUE1790051572",
"linkid": "quest-apartment-hotels",
"type": "Breach",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '1,991,613',
                        'industry': 'Hospitality',
                        'location': 'Australia',
                        'name': 'Quest Apartment Hotels',
                        'type': 'Business'}],
 'attack_vector': 'Third-party software vulnerability',
 'customer_advisories': 'Vigilance against scams, passport validity '
                        'confirmation',
 'data_breach': {'number_of_records_exposed': '1,991,613',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Passport numbers',
                                              'Driver’s licence details',
                                              'Credit card information (with '
                                              'and without CVVs)',
                                              'Vehicle registration numbers',
                                              'NDIS numbers',
                                              'Medicare card details']},
 'date_detected': '2024-08-17',
 'date_publicly_disclosed': '2024-08-19',
 'description': 'A significant data breach at Quest Apartment Hotels has '
                'compromised the personal information of 1,991,613 customers, '
                'including passport numbers, driver’s licence details, and '
                'credit card information (some with CVV codes). The breach '
                'originated from a third-party software vulnerability '
                'exploited by an unknown threat actor on 17 August 2024.',
 'impact': {'brand_reputation_impact': 'Significant',
            'data_compromised': '1,991,613 customer records, including '
                                'passport numbers, driver’s licence details, '
                                'credit card information (with and without '
                                'CVVs), vehicle registration numbers, NDIS '
                                'numbers, and Medicare card details',
            'downtime': 'Website outage',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': 'Website (third-party software)'},
 'initial_access_broker': {'data_sold_on_dark_web': 'No evidence found',
                           'entry_point': 'Third-party software vulnerability'},
 'investigation_status': 'Ongoing',
 'motivation': ['Payment fraud', 'Identity theft', 'Intelligence gathering'],
 'post_incident_analysis': {'corrective_actions': 'Cybersecurity improvements',
                            'root_causes': 'Third-party software '
                                           'vulnerability'},
 'references': [{'source': 'Cyber incident description'}],
 'regulatory_compliance': {'regulatory_notifications': 'Office of the '
                                                       'Australian Information '
                                                       'Commissioner (OAIC), '
                                                       'Department of Foreign '
                                                       'Affairs and Trade '
                                                       '(DFAT)'},
 'response': {'communication_strategy': 'Customer notifications, public '
                                        'disclosure',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes (Victoria Police, Australian '
                                          'Signals Directorate, Australian '
                                          'Cyber Security Centre)',
              'remediation_measures': 'Cybersecurity improvements',
              'third_party_assistance': 'Forensic analysis'},
 'stakeholder_advisories': 'Cooperation with Australian authorities, customer '
                           'notifications',
 'threat_actor': 'Unknown',
 'title': 'Quest Apartment Hotels Data Breach Exposes Nearly 2 Million '
          'Customers, Including Sensitive Financial and Identification Details',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Third-party software vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.