Wednesday 23 September 2026Western Australia edition
Western Australia Today

Local stories, community first — Perth and beyond.

Quest Apartment Hotels Urges Customers to Replace Passports and Licences After Data Breach

Quest Apartment Hotels has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation revealed additional information had been leaked. The breach exposed sensitive customer information, including passports, driver's licences, and credit card numbers with CVV numbers.

SR
By Staff Reporter
News reporter · Updated 1 day ago

A recent security breach at Quest Apartment Hotels has led to the exposure of sensitive customer information, prompting the company to advise affected individuals to replace their passports and driver's licences.

In August, Quest discovered unauthorised access to a database system through a vulnerability in a third-party service provider. Initially, the company informed customers that data from before June 2025, including full names, email addresses, and other contact details, had been exposed.

However, a further investigation revealed that additional information, including passports, driver's licences, credit card numbers with CVV numbers, and other personal information, had been leaked. Quest has since notified affected customers via email and text message.

In an email to a concerned customer, Quest wrote: "If your driver's licence number was affected, consider contacting your local road authority about obtaining a replacement licence." The email also advised customers to contact the Australian Passport Office or relevant issuing authority for non-Australian passports to discuss whether their passport should be flagged or reissued.

Steven Cooper from NSW received a text message from Quest, which stated: "Our forensic data analysis has confirmed that some additional categories of your personal information were involved in the data security incident we previously notified you about." Mr Cooper had previously been a victim of multiple data breaches, including those affecting Origin, Optus, and Medibank.

"It's pretty annoying to be listed, you know, three or four times," Mr Cooper said. "The Origin one came, and then the Quest one came quite quickly after." He was told that his information, credit cards, including CVV numbers, car registration, and date of birth had been leaked.

Another customer, who chose to remain anonymous, received an email from Quest stating that their credit cards and personal information had been leaked. They had stayed at Quest Apartments multiple times, used multiple credit cards, and had to cancel them and have their licence reissued.

Lizzy, who asked to use only her first name to protect her identity, said she was advised via text that her information, including her credit card details, was leaked six years ago during the COVID-19 pandemic. She had booked and paid for a Quest apartment with her credit card but couldn't stay due to COVID restrictions.

"It just seems strange that they've still got my credit card details on file, when really, all I did was pay for it online … even though I never ended up staying there and it's been six years," she said.

David Mansfield, managing director for Australasia at The Ascott Limited, said in a statement: "For the overwhelming majority of impacted individuals, the information identified at that preliminary stage was limited to a combination of name and contact information. Our forensic data analysis has now enabled us to determine the specific types of personal information affected."

Quest stated that the investigation found information relating to 1,991,613 customers was affected.

BusinessPerth

More from Business