"I am writing to inform you of a recent data security incident involving some of your personal information," reads an email sent to Quest guests after the company identified unauthorised access to a database system on Monday, 17 August 2026, the hotel chain told customers.
Quest customer notification — 17 August 2026
The Register published an email it said was shared by a reader that opened with the sentence above and carried the subject line "Important Security Update Regarding Your Quest Data." According to that message, Quest "identified unauthorised access to a database system and immediately took steps to contain the incident." The company attributed the incident to "a vulnerability through our third-party service provider."
Data types disclosed: names, contact details and some dates of birth
Quest told customers the exposed records "relate to records from before June 2025" and involve guests' full names and "Your email and/or other contact details." When pressed by The Register, the company added that "A small number of data entries also involve Date of Birth." The Register observed that, because of those elements, "whoever accessed this info is now in a decent position to attempt identity fraud."

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildScope and possible international exposure
Quest operates more than 120 properties, the company says, with most properties in Australia and some in New Zealand and Fiji. The Register found Quest listings on third‑party travel booking platforms including Expedia, Wotif and Booking.com, and noted that presence on those sites "suggesting overseas visitors who stayed in the company’s properties may also be at risk." Quest has been operating "more than 30 years," raising questions about how far back affected records may reach; the company told The Register the exposed records "relate to records from before June 2025" but did not specify an earlier cutoff.
What Quest reports it has done so far
In response to The Register's inquiries, Quest said it has contacted all affected guests, "contained and fixed the leaky systems," completed remediation, commenced forensic investigations, and hired external cyber security and privacy advisers. The company did not identify the third‑party service provider that it said was the source of the vulnerability, nor did it disclose how the unauthorised access occurred or the number of customers impacted.
How guests, enterprise security teams, and travel‑booking platforms are likely to react
- Guests: Those whose contact details or dates of birth were exposed will most likely need to monitor for phishing and identity‑based fraud; Quest said it has contacted "all affected guests."
- Enterprise security teams and procurement leaders: Teams responsible for third‑party risk and vendor security will watch how Quest's investigation attributes the incident to an external database operator, and will want details about the vulnerability and the mitigations Quest has applied.
- Travel‑booking platforms: Sites such as Expedia, Wotif and Booking.com — where The Register found Quest listings — may be alerted by customers or Quest itself if evidence emerges that bookings or overseas guest data were involved; the Register noted those listings when reporting that overseas visitors "may also be at risk."
This remains a developing story. Quest has said it contained the incident and retained external advisers and forensic investigators, but it has not named the implicated third‑party database operator, disclosed the attack method, or quantified affected records. The central factual question the company's own timeline raises is explicit in The Register's reporting: given Quest's decades of operation and the company's statement that exposed records "relate to records from before June 2025," how far back do compromised records actually go?




