Quest tells customers to replace passports after security breach - ABC News & Headlines – Australian Broadcasting Corporation
Quest told customers that an investigation found additional information had been leaked. (ABC News: John Gunn)
Quest Apartment Hotels has issued warnings to affected customers to reissue their passports and replace their driver's licences after personal data was exposed.
The company initially advised customers that their information had leaked in August this year but did not detail the extent.
Customers told the ABC they had to reissue credit cards and licences.
Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation revealed additional information had been leaked.
In August, Quest said that it had identified unauthorised access to a database system "from a vulnerability through a third-party service provider".
It advised affected customers that their data from before June 2025, including full names, email addresses and other contact details, had been exposed.
But in new emails and text messages seen by the ABC, Quest told customers an investigation found additional information, including passports, driver's licences, credit card numbers including CVV numbers, and other personal information, had been leaked.
"If your driver's licence number was affected, consider contacting your local road authority about obtaining a replacement licence," it said.
"If your passport number was affected, contact the Australian Passport Office (or the relevant issuing authority for non-Australian passports) to discuss whether your passport should be flagged or reissued."
Quest contacted Steven Cooper from NSW via text message.
This text message was sent to multiple customers. (Supplied)
The text seen by the ABC said: "Our forensic data analysis has confirmed that some additional categories of your personal information were involved in the data security incident we previously notified you about."
Mr Cooper had been a victim of multiple data breaches, including the Origin, Optus and Medibank security leaks, which he said had been frustrating.
"It's pretty annoying to be listed, you know, three or four times," Mr Cooper said.
In this breach, he said he was told his information, credit cards, including CVV numbers, car registration and date of birth had been leaked.
Mr Cooper said he stayed with Quest quite often, so he had to change multiple credit card passwords on his joint accounts.
"They said that it's happening even with expired cards. So I guess that's the kind of currency that the hackers are interested in so they can defraud people," he said.
Another customer, who chose to remain anonymous, said Quest emailed them to say their credit cards and personal information had been leaked.
They had stayed at Quest Apartments several times and used multiple credit cards, and had to cancel them and have their licence reissued.
They said the whole process was time-consuming and inconvenient.
Currently, the waiting time to have your licence reissued and mailed to you, depending on the state, can be up to 14 days.
Getting a passport reissued can take up to six weeks to process according to the Australian Passport Office website.
Lizzy, who asked to use only her first name to protect her identity, said she was also advised via text that her information, including her credit card details, was leaked six years ago during the COVID-19 pandemic.
At the time, she couldn't stay at the Quest apartments because of COVID restrictions, but she said she booked and paid for the apartment with her credit card.
"It just seems strange that they've still got my credit card details on file, when really, all I did was pay for it online … even though I never ended up staying there and it's been six years," she said.
When she got the first text in August advising that her name and other details had been leaked, she said she didn't "really bother" to worry about it.
"I really just thought that text was a scam, so I didn't really think much of it. I didn't get a follow-up email about it," she said.
It was only when she got a follow-up text last week letting her know her credit card details were also leaked that she started to worry.
David Mansfield, managing director for Australasia at The Ascott Limited, said in a statement that earlier updates advised that: "For the overwhelming majority of impacted individuals, the information identified at that preliminary stage was limited to a combination of name and contact information.
"Our forensic data analysis has now enabled us to determine the specific types of personal information affected.
"I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected."
In a statement, Quest said the investigation found information relating to 1,991,613 customers was affected.
It outlined that the following additional information was compromised.


