Australian hotel chain leaks guests’ PII after breach at third-party database operator
Unknown parties know where you stayed last summer, down under, across 120 Quest properties
Australian aparthotel chain Quest has revealed it leaked customer data.
A Reg reader kindly shared an email from the chain with the subject line “Important Security Update Regarding Your Quest Data.”
That missive opens with unwelcome news that “I am writing to inform you of a recent data security incident involving some of your personal information.”
“On Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident,” the email continues. “The incident arose from a vulnerability through our third-party service provider.”
Exposed data “relates to records from before June 2025” and includes guests’ full name, plus what Quest described as “Your email and/or other contact details.”
The Register asked the company for comment, and it told us “A small number of data entries also involve Date...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE