Full Report
Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation revealed additional information had been leaked. In August, Quest said that it had identified unauthorised access to a database system "from a vulnerability through a third-party service provider". It advised affected customers that their data from before June 2025, including full names, email addresses and other contact details, had been exposed. But in new emails and text messages seen by the ABC, Quest told customers an investigation found additional information, including passports, driver's licences, credit card numbers including CVV numbers, and other personal information, had been leaked. https://www.questapartments.com.au/update
Analysis Summary
# Incident Report: Quest Apartment Hotels Data Breach
## Executive Summary
Quest Apartment Hotels suffered a significant data breach originating from a third-party service provider vulnerability, initially disclosed in August 2026. Subsequent forensic investigations revealed a much deeper level of compromise than first reported, including highly sensitive identity documents and financial data. The incident has forced thousands of customers to replace passports, driver's licenses, and credit cards.
## Incident Details
- **Discovery Date:** August 2026
- **Incident Date:** Ongoing/Discovered August 2026 (Data dates back to at least 2020)
- **Affected Organization:** Quest Apartment Hotels
- **Sector:** Hospitality
- **Geography:** Australia (Primary)
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-August 2026
- **Vector:** Vulnerability through a third-party service provider.
- **Details:** Attackers exploited a weakness in a third-party system to gain unauthorized access to Quest's database.
### Lateral Movement
- **Details:** Specific lateral movement techniques were not disclosed, but the breach expanded from a single entry point to a database containing over six years of historical customer data.
### Data Exfiltration/Impact
- **Details:** Initially, Quest reported exposure of names and contact details. In September 2026, the scope was updated to include:
- Passport numbers
- Driver's license numbers
- Credit card numbers (including CVV)
- Vehicle registration details
- Dates of birth
### Detection & Response
- **August 2026:** Quest identifies unauthorized access and notifies customers of a "limited" breach.
- **September 2026:** Forensic analysis confirms the compromise of high-value PII (Personally Identifiable Information).
- **September 23, 2026:** Quest issues urgent updates via email/SMS advising document replacement.
## Attack Methodology
- **Initial Access:** Exploitation of third-party software/service vulnerability.
- **Persistence:** Not explicitly disclosed.
- **Collection:** Data gathering included historical archives of customers who had not interacted with the brand in six years.
- **Impact:** Financial fraud risk and identity theft through the theft of primary identity documents.
## Impact Assessment
- **Financial:** High; includes costs of document replacement for customers and potential regulatory fines.
- **Data Breach:** High-volume exfiltration of sensitive identity documents and full credit card details (including CVV).
- **Operational:** Diversion of resources to forensic investigation and customer notification.
- **Reputational:** High; customers expressed frustration over the delay in revealing the full extent of the breach and the retention of data from 2020.
## Indicators of Compromise
- **Network indicators:** Not disclosed in public reporting.
- **File indicators:** Not disclosed.
- **Behavioral indicators:** Unauthorized access to a central database system via a third-party API or service link.
## Response Actions
- **Containment:** Identified and addressed the third-party vulnerability.
- **Eradication:** Conducted forensic data analysis to determine the full scope of leaked information.
- **Recovery:** Notified affected individuals via SMS and email with specific guidance on document replacement.
- **External Liaison:** Coordination with the Australian Passport Office and road authorities.
## Lessons Learned
- **Data Retention Policies:** Keeping sensitive credit card and ID data for six years (even for failed bookings) significantly increased the "blast radius" of the breach.
- **Incremental Disclosure:** The initial underestimation of the breach scope led to a secondary wave of customer frustration and potential prolonged exposure for victims.
- **Third-Party Risk:** Third-party providers remain a critical weak point in the hospitality supply chain.
## Recommendations
- **Implement Strict Data Minimization:** Purge sensitive payment and ID data as soon as the business requirement expires (e.g., after check-out or booking cancellation).
- **Enhanced Third-Party Audits:** Perform rigorous security assessments of all third-party vendors with database access.
- **Encryption:** Ensure that sensitive fields such as CVV and ID numbers are encrypted at rest with robust key management.
- **Identity Protection Services:** Offer credit monitoring and identity protection services to customers whose passports and licenses were exposed.