A data breach at Quest Apartment Hotels has affected nearly 2 million customers, including more than 400,000 whose passport, driver licence and credit card numbers were exposed.
The hotel chain first disclosed the security incident on 19 August, saying a database had been accessed illegally and that the information involved mostly “names, email addresses, and/or other contact details”, along with a small number of birthdate details.
In a mid-September update, Quest confirmed the data breach impacted some 1,991,613 customers, and in some cases passport, licence, and credit card numbers were exposed.
“We have now completed a forensic data analysis into the incident,” wrote David Mansfield, managing director of Quest’s parent company The Ascott Limited.
“All the information identified relates to records from before June 2025.”
Information Age asked Quest when it first became aware that passport and credit card numbers had been affected but did not receive a response before publication.
Quest has engaged in ongoing cooperation with the Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre, and Victoria Police.
Credit card CVVs among stolen data
Quest confirmed the contact information of affected customers included “some combination” of names, addresses, contact phone numbers, and email addresses.
Some 104,268 customers saw their passport and/or driver licence number affected, while 225,300 vehicle registration numbers were also caught in the incident.
Though Quest did not initially signal that financial data had been compromised, its September update confirmed 46,727 credit card numbers with their associated CVVs were affected.
An additional 297,739 credit cards without CVV details were also affected, while Quest emphasised that an unspecified number of the exposed cards were expired.
Vaughan Shanks, chief executive of Melbourne-based incident response vendor Cydarm Technologies, said the most “harmful” data stolen in the breach was the non-expired card numbers with CVVs included.
“Combined with name and address, these can immediately be used for online fraudulent purchases,” said Shanks.
“Users whose credit card numbers were stolen, with or without CVVs, should cancel those cards immediately to avoid fraud.
“Anyone else affected should maintain a heightened awareness of the risks of identity theft and email-based fraud, especially from scammers pretending to be a government agency.”
NDIS numbers were also impacted for a pool of 271 customers, while some 46 individuals saw their Medicare card numbers exposed.
Quest emphasised not every type of information was affected for every individual in the breach.
“We are contacting impacted individuals directly to advise them of the specific categories of personal information relating to them that was affected, as well as the practical steps they can take in response, and the support available,” wrote Mansfield.
What can criminals do with a stolen passport number?
Quest confirmed passport numbers were affected during the August incident, though the company stressed that no scanned copies of passport documents were included.
The Department of Foreign Affairs and Trade also acknowledged the incident and said affected passports remained safe to use for international travel.
“Your passport number cannot be used to obtain a new passport,” wrote the department.
“Robust controls are used to protect passports from identity takeover, including sophisticated facial-recognition technology.”
RMIT associate professor in cybersecurity Nalin Arachchilage told Information Age a passport number was a “highly valuable piece of personal information” even if it was unlikely to enable identity theft by itself.
“Here is the thing — cybercriminals rarely use just one piece of stolen data,” said Arachchilage.
“Instead, they combine information from multiple breaches, social media, and public sources to build a detailed profile of a person.
“My main concern here is that passport numbers can be used to make scams look more convincing.
“If a scammer already knows your name, contact details, and passport number, they can create highly personalised phishing emails, text messages, or even telephone calls that appear legitimate.”
All quiet on the dark web
Quest explained its data breach began with a website outage on 17 August – which led the hotel chain to identify that a threat actor had exploited a vulnerability in an unnamed third-party service provider’s software to gain access to a Quest “environment”.
Quest took immediate steps to contain the incident and has since made “cybersecurity improvements” to reduce the risk of such an incident reoccuring.
At the time of writing, Information Age has not located any related data leaks on the dark web or prominent hacking forums.
Information Age also understands no known threat actor has publicly claimed responsibility for the incident.
Shanks said the lack of information made it “difficult” to fully categorise the incident.
“It seems that no one has claimed responsibility for the breach, and we don’t know how the data was accessed, nor who the third-party provider was,” said Shanks.
“The lack of a public extortion demand suggests that this dataset was possibly used by criminals for payment card fraud or identity theft, or by a nation state actor to enrich target profiles for intelligence collection purposes.”
In his statement, Mansfield said he recognised the “concern this incident has caused”, and thanked customers for their patience during the company’s month-long investigation.
“On behalf of Quest, I sincerely apologise to those who have been affected,” said Mansfield.