
Quest Apartment Hotels Data Breach: What Travellers Should Check
Quest says unauthorised access through a third-party service provider exposed some older customer contact records, creating a risk of convincing booking and travel-themed phishing.
The short version
What you need to know
- Quest says it identified unauthorised access on 17 August 2026 involving a vulnerability through a third-party service provider. It says the incident has been contained and remediation is complete, although the investigation continues.
- The affected records predate June 2025 and mainly contain names, email addresses and/or other contact details. Quest says a small number include dates of birth.
- Quest says it has contacted people who may be affected. A VPN cannot remove information from the affected database or make an unexpected breach, booking or refund message genuine.
What did Quest Apartment Hotels disclose?
Quest Apartment Hotels says it identified unauthorised access to customer information on 17 August 2026. According to its update, the access resulted from a vulnerability through a third-party service provider rather than an incident involving hotel Wi-Fi or guests' devices.
Quest says the incident has been contained and remediation is complete. It is still investigating and working with the relevant authorities, so the available statement should not be stretched into claims about an attacker, motive or wider impact that the company has not confirmed.
What customer information may be involved?
Quest says the affected records date from before June 2025 and mainly contain names, email addresses and/or other contact details. A small number also include dates of birth. The company has not published an affected-person count in its update.
Contact information can help scammers make a fake booking change, refund, loyalty-account alert or payment request sound credible. A message containing your real name or an old travel detail is not proof that its sender represents Quest.
How to verify a breach notice safely
Quest says it has contacted people who may be affected and that anyone who has not received a notice is unlikely to be affected. Unlikely is not the same as a guarantee, particularly while the investigation remains open.
Do not use a phone number or sign-in link supplied only by an unexpected email or text. Type questapartments.com.au into your browser yourself, navigate to the company's update, and use contact details obtained independently from the official website or a previous genuine booking record. Be suspicious of urgent requests for card details, passwords, one-time codes, refunds or fees.
What travellers can do now
Keep the legitimate notice and remain alert for messages referring to old Quest stays or reservations. Open booking accounts through their official apps or addresses, use a unique password for each travel service, enable multi-factor authentication where available, and review account sessions if a suspicious message led you to sign in.
If you entered a password on a questionable page, change it through the genuine service and anywhere else it was reused. Contact your card issuer promptly if you disclosed payment details or see unfamiliar transactions. Nothing in Quest's update indicates that this incident involved public Wi-Fi.
Where a VPN helps — and where it does not
A reputable VPN can encrypt traffic between your device and its VPN server on an untrusted local network. That can provide useful connection privacy when accessing accounts from an airport, hotel or café.
A VPN cannot undo unauthorised access to the affected database, remove exposed contact records, identify a genuine breach notice or prevent information from being used in phishing. This incident calls for independent message verification and careful account security, not simply a different IP address.
VPN Rocks view
Older contact details may appear less sensitive than passwords or payment information, but they can still add credibility to targeted travel scams. Readers should judge every request by the action it demands, not by how much accurate personal context it contains.
Quest's update provides useful boundaries around the known data and notification process while acknowledging that the investigation continues. Customers should follow those confirmed facts without assuming every past guest was affected or that the incident involved hotel Wi-Fi.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.