Quest data breach exposes nearly 2 million customers' details
Quest Apartment Hotels' cyberattack exposed data on 1.9 million customers, including credit cards, passports and Medicare details.
Quest Apartment Hotels was hit by a cyberattack on 17 August. The cyberattack exploited a flaw in third-party software.
A review found about 1.9 million customer records were affected. Most held names and contact details.
Some also held credit card numbers, passport details and Medicare information. All affected data came from before June 2025.
The company is telling those affected. It is working with the Office of the Australian Information Commissioner, the Australian Cyber Security Centre and Victoria Police.
Quest told customers to watch for suspicious emails, texts and calls.
- 1,991,613
- Customers affected
- August 17
- Discovery date
- David Mansfield
- Managing director
Why it mattersAffected customers face identity theft and fraud risks. They should monitor their accounts and credit reports.
AustraliaMillions of Australian Quest customers need to check if their financial and personal details were exposed and take steps to protect themselves against identity fraud.
✓ Claims checked against the source. checked 6 d ago



