# Quest Apartment Hotels Data Breach Escalates: Customers Told to Replace Passports and IDs

The cybersecurity landscape has witnessed another significant escalation as Quest Apartment Hotels, one of Australia's largest hotel chains, has issued urgent warnings to customers affected by a massive data breach. The company now advises victims to replace their passports and reissue driver's licences after its ongoing forensic investigation revealed that far more sensitive information was compromised than initially disclosed. This development serves as a stark reminder that data breach incidents rarely remain static—the full scope of damage often unfolds over months of painstaking forensic analysis.

When Quest Apartment Hotels first disclosed a security incident in August, the initial notification appeared manageable: unauthorized access to a database system through a vulnerability in a third-party service provider, potentially exposing customer names, email addresses, and contact details. For the nearly two million customers affected, this was concerning but not catastrophic. However, in new communications sent via email and text message, Quest has now revealed that the investigation uncovered additional categories of compromised personal information, including passports, driver's licences, credit card numbers complete with CVV security codes, car registrations, and dates of birth—a treasure trove of personally identifiable information for cybercriminals.

## The Evolving Nature of Data Breach Disclosure

The Quest apartment data breach timeline reveals a troubling pattern in how cyber incidents evolve. When the initial breach was detected in August 2024, the company's preliminary assessment suggested limited data exposure. But as forensic analysts delved deeper into the compromised database systems, they discovered that the hackers had accessed significantly more sensitive records. David Mansfield, managing director for Australasia at The Ascott Limited, which operates Quest, acknowledged this in a statement, explaining that earlier updates advised that for the majority of impacted individuals, the information identified at that preliminary stage was limited to a combination of name and contact information. He noted that their forensic data analysis has now enabled them to determine the specific types of personal information affected.

Quest has confirmed that the breach investigation found information relating to 1,991,613 customers was affected—a massive exposure that puts the hotel chain's customer base at significant risk of identity theft and financial fraud. The compromised data categories include full legal names, residential addresses, email addresses, phone numbers, passport numbers, driver's licence numbers, credit card details including CVV numbers, car registration information, and dates of birth. This comprehensive data set provides cybercriminals with everything needed to commit sophisticated identity theft or launch targeted phishing campaigns.

## Real Victims, Real Consequences

Steven Cooper, a New South Wales resident, received the text message notification that his additional information had been compromised. As someone who has been victimized by multiple major data breaches—including the Origin Energy, Optus, and Medibank security incidents—Cooper expressed understandable frustration at being caught in yet another cyber security incident. "It's pretty annoying to be listed, you know, three or four times," he told the ABC. The repeat victimization highlights a growing concern in the cybersecurity community: as more organizations suffer breaches, attackers can aggregate stolen data across multiple incidents to build comprehensive profiles on individuals.

Cooper revealed that he had his credit card information, including CVV numbers, car registration details, and date of birth exposed in the Quest breach. Because he frequently stayed at Quest properties, he was forced to change multiple credit card passwords on his joint accounts. He noted that the hackers' interest in card data extends even to expired cards—information that could potentially be used for social engineering attacks or to establish fraudulent credit histories. "They said that it's happening even with expired cards. So I guess that's the kind of currency that the hackers are interested in so they can defraud people," Cooper observed, demonstrating a keen understanding of how stolen data retains value in the cybercrime economy.

## The Long-Term Impact of Data Breaches

Another Quest customer, who chose to remain anonymous, described the cascading consequences of the breach. Having stayed at Quest Apartments multiple times with various credit cards, they were forced to cancel all affected cards and have their driver's licence reissued. The process proved time-consuming and inconvenient, with licence reissuance taking up to 14 days depending on the state, and passport replacement potentially requiring six weeks of processing time through the Australian Passport Office. This administrative burden falls on the victims rather than the company whose security failure exposed their data—a source of considerable frustration for those affected.

The breach's reach extends even to individuals who never actually stayed at a Quest property. Lizzy, who asked to use only her first name to protect her identity, was shocked to discover that her credit card details from 2018—six years before the breach—had been compromised. She had booked and paid for an apartment during the COVID-19 pandemic but never stayed due to restrictions. "It just seems strange that they've still got my credit card details on file, when really, all I did was pay for it online… even though I never ended up staying there and it's been six years," she said. This revelation underscores a critical cybersecurity concern: organizations often retain customer payment data far longer than necessary, expanding their attack surface and amplifying the impact of any breach.

Lizzy admitted she initially dismissed the August text notification as a scam, a common response that cybersecurity experts warn could lead to victims ignoring legitimate breach notifications. It was only when she received the follow-up text last week revealing that her credit card details were also compromised that she began to worry. This delayed recognition demonstrates the challenge organizations face in communicating breach information effectively to consumers who are increasingly skeptical of unsolicited communications, even legitimate ones.

## Official Recommendations and Response

Quest has provided specific guidance to affected customers regarding the exposed passport and driver's licence information. In an email obtained by the ABC, the company advised: "If your driver's licence number was affected, consider contacting your local road authority about obtaining a replacement licence. If your passport number was affected, contact the Australian Passport Office (or the relevant issuing authority for non-Australian passports) to discuss whether your passport should be flagged or reissued."

The Australian Department of Foreign Affairs and Trade (DFAT) has acknowledged the cyber incident affecting Quest Apartments and Hotels. In a statement, the department sought to reassure affected travelers: "If your Australian passport number was compromised in this data breach, your passport is still safe to use for international travel. Your passport number cannot be used to obtain a new passport. Robust controls are used to protect passports from identity takeover, including sophisticated facial-recognition technology." This official statement provides some reassurance while acknowledging the seriousness of the situation.

## Lessons for the Cybersecurity Community

The Quest Apartment Hotels data breach serves as a critical case study for cybersecurity professionals and tech enthusiasts alike. First, it highlights the dangers of third-party service provider vulnerabilities—the initial entry point for the attackers. Supply chain attacks continue to represent one of the most significant threat vectors in modern cybersecurity, as attackers recognize that compromising a single vendor can provide access to multiple organizations' sensitive data. Second, the incident demonstrates the importance of data minimization principles: retaining customer credit card data for six years after a transaction, especially for bookings that never resulted in stays, represents a significant security liability.

The breach also underscores the evolving nature of threat actor behavior. Cybercriminals are not merely interested in immediate financial gain through credit card fraud; they understand the long-term value of comprehensive personal information for identity theft and social engineering attacks. The collection of passports, driver's licences, and other government-issued identification details represents a sophisticated long-game strategy that could enable future criminal activities.

## Conclusion

The Quest Apartment Hotels data breach escalation from contact information to full identity credentials represents a worst-case scenario for the nearly two million affected customers. As forensic investigations continue to reveal the true scope of compromised data, the incident reinforces several fundamental cybersecurity truths: no organization is immune to breaches, third-party vulnerabilities pose significant risks, and the full impact of a security incident may not be known for months. For the cybersecurity community, this breach serves as both a cautionary tale and a call to action—emphasizing the need for robust data protection practices, minimal data retention policies, and comprehensive incident response planning that anticipates evolving disclosures. As affected customers navigate the lengthy process of replacing passports, reissuing licences, and canceling credit cards, the incident stands as a powerful reminder that in the digital age, our personal information is both our most valuable asset and our most significant vulnerability.