Quest Apartment Hotels is investigating a security breach involving customer personal information, after identifying unauthorised access to a database system on Monday, 17 August 2026. The company said the access occurred through a vulnerability involving a third-party service provider.

According to information sent to affected customers, the compromised records relate to information held before June 2025. The data includes customers' full names, email addresses and other contact details. A small number of records also contain customers' dates of birth.

Quest said it acted immediately after discovering the unauthorised access. The company said it took steps to contain the incident and secure the affected systems, and stated that the breach had been contained.

The company has notified Australia's Office of the Australian Information Commissioner and the Australian Cyber Security Centre about the incident. Quest has also told customers that it will contact them if its continuing investigation identifies additional information relevant to them or if further action is required.

The precise scale of the breach has not yet been publicly established. The company is continuing its investigation into the affected database and the circumstances surrounding the unauthorised access. Questions remain about exactly how many customers were affected and whether additional information may have been accessed.

Quest has warned customers to be particularly cautious about unexpected emails, links and attachments. Customers should not automatically trust a message simply because it appears to come from a hotel or accommodation provider, particularly while a security incident is being investigated.

The incident is significant because accommodation businesses can hold a range of personal information about guests and customers. Even where financial or highly sensitive information is not involved, exposed names and contact details can potentially be used in phishing or impersonation attempts.

Quest is owned by The Ascott Limited, which also operates other accommodation brands including Citadines and Oakwood in Australia and internationally.

The company has apologised to customers and said privacy and security remain important priorities. The investigation will determine the full extent of the incident and whether any additional information was compromised.

For affected customers, the immediate priority is to remain alert for suspicious communications, avoid clicking unexpected links and verify requests through official channels rather than responding directly to unusual messages.