Overview
- Quest told customers it discovered unauthorised access to a database system that exploited a vulnerability in a third‑party service provider and took immediate steps to secure the systems.
- Forensic work so far shows the accessed records relate to data held before June 2025 and mainly include full names, email addresses and other contact details with a small number of dates of birth.
- The company says the incident has been contained, remediation work finished, and identified customers have been notified while Quest continues its forensic investigation and is working with the vendor.
- Quest has informed the Office of the Australian Information Commissioner and the Australian Cyber Security Centre, but it has not disclosed how many customers were affected and media outlets are seeking more detail.
- Customers were warned to expect phishing risk from unexpected calls, texts or emails and to avoid clicking links or opening attachments, and the case highlights the wider cyber risk hotels face when they rely on external IT vendors.