Overview
- Quest identified unauthorised access to a database through a third‑party service provider and says it contained the incident on Monday.
- Forensic work so far shows the accessed records date from before June 2025 and mainly include full names, email addresses and other contact details with a small number of dates of birth.
- A media report has estimated about 1.7 million guest records may be affected and up to 1,700 dates of birth were exposed, but Quest has not confirmed those figures pending its investigation.
- Quest has notified affected customers by email, reported the incident to the Office of the Australian Information Commissioner and the Australian Cyber Security Centre, and completed remediation work with the third party.
- Security experts say the main risk is targeted phishing and identity fraud and that this case highlights how vulnerabilities at vendors can expose large volumes of customer data for hotel groups operating across Australasia.