Customer information has been accessed by hackers through a third-party provider, accommodation chain Quest Apartment Hotels announced on Wednesday.

The serviced apartment company is one of the largest in Australia, with more than 120 locations across the country, as well as others in New Zealand and Fiji.

"Unauthorised access to a database system" was identified on Monday following "a vulnerability through a third-party service provider", Quest said in a statement.

"We immediately took steps to contain the incident and secure the affected systems," the company said.

"The incident has been contained, and remediation work has been completed."

Information exposed in the breach included records from before June 2025, Quest said, and "primarily involves names, email addresses, and/or other contact details" such as street addresses, but no financial information.

"A small number of data entries also involve date of birth," the company said.

Information Age understands more than 1.5 million records were potentially involved, but very few included dates of birth.

Quest would not name the third-party service provider when contacted for comment, but said it was following appropriate measures to notify government regulators and inform affected customers.

"We have contacted those we have identified as potentially affected to notify them and provide support, and we will continue to do so if our investigation identifies any further impact," the company said.

"If you do not receive a notification from us, it is unlikely that your personal information has been affected."

Quest said it had engaged external cybersecurity and privacy experts, and its forensic analysis is ongoing.

"The security of our guests’, staff and partners’ information remains our absolute priority," it said.

The announcement of Quest's third-party breach comes after other recent data breach notifications from the likes of Origin Energy, GP network Partnered Health, and Lifeline.