Quest Apartment Hotels, the Australasian accommodation chain owned by Singapore-based The Ascott Limited, has confirmed that a database intrusion first disclosed in August 2026 was substantially worse than initially reported. A mid-September forensic update from managing director David Mansfield put the total at approximately 1,991,613 affected customers, with Information Age reporting that 46,727 credit card numbers were among the exposed records, including thousands of CVV security codes. Cyber Daily's coverage of the same update headlines the figure as "almost 50,000" cards. The intrusion is attributed to a vulnerability in an unnamed third-party technology provider, not Quest's own infrastructure.
What Happened
Quest identified unauthorised access to a database system on Monday, 17 August 2026. Head Topics reports the company first noticed an outage on its website that day, with subsequent investigation revealing what Quest described as "a malicious attack" exploiting a flaw in a third-party service provider's software. ABC News, which first obtained the customer notification email on 19 August, quoted Quest's statement: "We immediately took steps to contain the incident and secure the affected systems. The incident has been contained."
The initial disclosure was narrow in scope. Quest told customers the compromised records pre-dated June 2025 and consisted mostly of "names, email addresses, and/or other contact details," with a small number of entries including dates of birth. Several outlets reporting in that first window, including Australian Cyber Security Magazine and NewsAffinity, explicitly noted that on the evidence released at the time, payment card details and passwords did not appear to have been taken.
That picture changed on 16 September, when Mansfield published a forensic update. "We have now completed a forensic data analysis into the incident," he wrote, per Information Age. "All the information identified relates to records from before June 2025." The scale and sensitivity both jumped sharply. Mansfield added, as quoted by Head Topics: "I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected."
Accounts of scale diverged before the forensic work completed. NewsAffinity, writing in the earlier window, noted Quest had not put a number on the impact and that "some Australian reporting has pointed to as many as 1.5 million records potentially involved." ThreatVectr reported that Quest and Ascott had not responded to requests for a figure. The company's own September number, 1,991,613, is now the authoritative count and supersedes those earlier estimates.
What Was Taken
Quest confirmed that affected contact information included "some combination" of names, addresses, contact phone numbers and email addresses. Beyond that baseline, Information Age reports the following breakdown from the September update:
- 1,991,613 customers affected in total
- 104,268 customers with passport and/or driver licence numbers exposed
- 225,300 vehicle registration numbers caught in the incident
- 46,727 credit card numbers exposed, described by Cyber Daily as "almost 50,000"
- Thousands of CVV security codes exposed alongside card numbers, per Information Age
Information Age characterises the identity-document and financial exposure as affecting "more than 400,000" customers in aggregate, a figure that appears to encompass the overlapping categories above rather than any single data type.
Head Topics additionally reports that Medicare numbers were among the compromised data. That claim does not appear in the other sources reviewed and should be treated as unconfirmed pending direct verification from Quest or the OAIC.
The CVV exposure is the detail that changes the threat model. Card numbers alone have limited standalone value against modern fraud controls; card number plus expiry plus CVV is a functionally complete card-not-present payment instrument. Combined with the verified names, addresses and phone numbers in the same dataset, the stolen records constitute ready-made kits for online fraud and for high-credibility social engineering against cardholders.
Information Age asked Quest when it first became aware that passport and credit card numbers had been affected. The company did not respond before publication. That gap, between the 19 August "mostly contact details" characterisation and the 16 September confirmation of CVV exposure, is roughly four weeks during which affected cardholders had no reason to monitor or cancel their cards.
Why It Matters
This is a supply chain incident wearing a hospitality brand's name. Quest's own network was not breached; the attackers came through a vendor holding or processing customer data on Quest's behalf. Insurance Business, covering the incident's implications for cyber underwriting, quoted Kash Sharma, managing director APAC at BlueVoyant: "For businesses, the detail that matters most is that this breach reportedly originated through a vulnerability in a third-party service provider, not Quest's own front door." Sharma described a pattern running "across healthcare, telecommunications, energy, and now hospitality: attackers going through the vendor ecosystem, where visibility is weakest."
The liability question is the one underwriters keep returning to. Garrett Droege, fintech and digital asset leader at WTW, told an InsuranceFest 2026 panel in Santa Monica in July: "A lot of people think they're outsourcing that, like someone else has the data and so we don't have to worry about it." Droege added that nearly any major cyber event, traced back far enough, involves a third party that left a back door open. Quest is the entity notifying regulators, notifying two million customers and absorbing the reputational damage, regardless of whose code contained the flaw.
There is a second, distinctly Australian angle. Every compromised record pre-dates June 2025, meaning this data was at least 15 months stale when it was stolen. Head Topics notes that experts say the incident raises fresh questions about data retention periods, and points to the federal privacy law overhaul requiring organisations to destroy or actively de-identify personal information once it is no longer needed. Card numbers with CVVs attached to bookings more than a year old represent retained risk with no corresponding business value. CVV storage in particular sits awkwardly against PCI DSS requirements, which prohibit retention of sensitive authentication data after authorisation. None of the sources reviewed clarify whether the CVVs were held by Quest, by the third-party provider, or in what form.
The third-party provider has still not been named publicly. Until it is, other organisations using the same vendor have no way to assess their own exposure to the same flaw.
The Attack Technique
Details on the intrusion mechanics remain thin. What is consistently reported across all eight sources is the initial access vector: exploitation of a vulnerability in a third-party service provider's software that granted access to a Quest database system. Quest's own wording, per Cyber Daily, is that it "identified unauthorised access to a database system arising from a vulnerability through a third-party technology provider."
Head Topics adds one operational detail of note: the incident surfaced as a website outage on 17 August, with the malicious attack discovered during the investigation of that outage. That suggests detection was reactive, triggered by a service disruption rather than by security monitoring catching the database access directly.
No threat actor has been named or attributed. No ransomware claim, extortion demand or dark web listing has been reported in any source reviewed. No CVE or specific product has been identified for the exploited vulnerability, and Quest has not named the provider. ThreatVectr, tracking the vendor-route pattern, drew a parallel to its 21 August reporting on a SickKids Hospital breach that followed the same path through a supplier's software flaw.
Quest states the incident has been contained and, per Australian Cyber Security Magazine and NewsAffinity, that remediation work is complete.
What Organizations Should Do
Inventory where card data actually lives, including at vendors. The gap between "we don't store CVVs" and "our booking platform vendor does" is where this incident happened. Map every third party that touches payment data and confirm in writing what each retains and for how long.
Enforce retention limits and prove they run. Records from before June 2025 should not have been holding live card numbers and CVVs. Write retention windows into policy, automate deletion or de-identification, and audit that the jobs are executing rather than assuming they are.
Make vendor security contractually visible. Require notification SLAs, patch commitments, evidence of vulnerability management, and audit rights. Pair contractual controls with continuous external monitoring of vendor attack surface, since contracts do not detect an unpatched system.
Build incident scoping that does not underestimate. Quest's first notification told customers the data was mostly contact details; the CVV exposure surfaced four weeks later. Where forensics are incomplete, state that plainly in customer communications rather than describing preliminary findings as the full picture, and have a pre-planned process for issuing an upgraded notification fast.
Treat website outages as potential security events. The incident was found while investigating an availability problem. Route unexplained service disruptions through security triage, not just operations.
Plan payment-specific response separately from PII response. Exposed CVVs warrant immediate card reissuance coordination with acquirers and issuers, not just a credit monitoring offer. Have those escalation paths defined before you need them.
For affected customers: Quest is advising vigilance against unexpected emails, texts and phone calls, particularly any requesting personal, financial or account information, and warns against clicking links or opening attachments even in messages that appear to come from Quest. Anyone who booked with Quest before June 2025 should treat any card used for that booking as compromised and request reissuance, regardless of whether a notification email arrived.
Quest says it is cooperating with the Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre and Victoria Police, and has engaged external cybersecurity and privacy advisers.
Sources: Quest breach included thousands of credit card CVVs Information Ag... | Quest Hotels data breach: Almost 2m impacted, almost 50k credit car... | Quest Apartment Hotels customers' personal data ... - ABC News | Quest Hotels breach puts vendor liability under the microscope Ins... | Quest Apartment Hotels confirms customer data breach linked to ... | Quest Apartment Hotels Data Breach: Customer Names and Emails Expos... | Nearly two million Quest Apartment Hotels customers affected by dat... | Quest’s Data Breach Started With a Supplier, Not Its Own Systems –...