Quest says third-party database breach exposed hotel guests’ personal data across its properties

Quest says unauthorized access to a database run by a third-party service provider exposed guest personal information tied to stays at its hotel properties. The company says it discovered the incident on August 17, 2026, and that the exposed records date from before June 2025; known data includes full names, email addresses and other contact details, and in a smaller number of cases dates of birth. Quest has not named the provider, attack method, or number of affected guests.
Why it matters: Guests may now face phishing and identity-fraud risk tied to real stay history and contact details. Affected users should watch for targeted scam messages and Quest needs to disclose scope, impacted systems, and the third-party involved so customers and defenders can assess exposure.

Sources

Australian hotel chain leaks guests’ PII after breach at third-party database operator
2026.08.19 100% relevant
This article appears to be the first concrete report of Quest disclosing a third-party database breach affecting guest personal data.
← Back to all stories