{"id":23508,"date":"2026-08-25T23:39:23","date_gmt":"2026-08-25T23:39:23","guid":{"rendered":"https:\/\/scannn.com\/australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator\/"},"modified":"2026-08-25T23:39:23","modified_gmt":"2026-08-25T23:39:23","slug":"australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator","status":"publish","type":"post","link":"https:\/\/scannn.com\/lv\/australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator\/","title":{"rendered":"Australian hotel chain leaks guests\u2019 PII after breach at third-party database operator"},"content":{"rendered":"\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\">\n<p class=\"kicker \" style=\"\">cyber-crime<\/p>\n<p class=\"subtitle \" style=\"\">Unknown parties know where you stayed last summer, down under, across 120 Quest properties<\/p>\n<\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\">\n<p>Australian aparthotel chain Quest has revealed it leaked customer data.<\/p>\n<p>A <em>Reg<\/em> reader kindly shared an email from the chain with the subject line \u201cImportant Security Update Regarding Your Quest Data.\u201d<\/p>\n<p>That missive opens with unwelcome news that \u201cI am writing to inform you of a recent data security incident involving some of your personal information.\u201d<\/p>\n<p>\u201cOn Monday, 17 August 2026, we identified unauthorised access to a database system and immediately took steps to contain the incident,\u201d the email continues. \u201cThe incident arose from a vulnerability through our third-party service provider.\u201d<\/p>\n<p>Exposed data \u201crelates to records from before June 2025\u201d and includes guests\u2019 full name, plus what Quest described as \u201cYour email and\/or other contact details.\u201d<\/p>\n<p>The Register asked the company for comment, and it told us \u201cA small number of data entries also involve Date of Birth.\u201d<\/p>\n<p>Which means whoever accessed this info is now in a decent position to attempt identity fraud.<\/p>\n<p>Quest did not, however, identify the third-party that was the source of the breach, how the breach happened, or the number of customers impacted by the leak.<\/p>\n<p>The company also ignored our question about the extent of the lost data. Quest started operating more than 30 years ago, so we\u2019re keen to know how far back this leak goes.<\/p>\n<p>Quest operates over 120 properties, most in Australia, plus some in New Zealand and Fiji. <em>The Register<\/em> has found listings for Quest properties on popular third-party travel booking sites such as Expedia, Wotif, and Booking.com \u2013 suggesting overseas visitors who stayed in the company\u2019s properties may also be at risk.<\/p>\n<p>The accommodation outfit told The Register it has contacted all affected guests, contained and fixed the leaky systems, completed remediation, commenced forensic investigations, and hired external cyber security and privacy advisers.<\/p>\n<p>This is a developing story and <em>The Register<\/em> will update it as more information becomes available. \u00ae<\/p>\n<\/div>\n<p><a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/08\/19\/australian-hotel-chain-leaks-guests-pii-after-breach-at-third-party-database-operator\/5289341?utm_source=tldrinfosec\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>cyber-crime Unknown parties know where you stayed last summer, down under, across 120 Quest properties Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader kindly shared an email from the chain with the subject line \u201cImportant Security Update Regarding Your Quest Data.\u201d That missive opens with unwelcome news that \u201cI am [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":23509,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-23508","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"_links":{"self":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/comments?post=23508"}],"version-history":[{"count":0,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23508\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media\/23509"}],"wp:attachment":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media?parent=23508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/categories?post=23508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/tags?post=23508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}