Australian aparthotel chain Quest has disclosed a customer data incident after unauthorized access to a database system, according to The Register, which reviewed a customer notification email and obtained additional comment from the company. The notice said Quest identified the unauthorized access on Monday, 17 August 2026, and “immediately” took steps to contain it, The Register reports. Quest attributed the incident to a vulnerability through a third-party service provider, but did not name that provider. The exposed information relates to records from before June 2025. According to The Register, the customer email said affected data included guests’ full names and “email and/or other contact details.” Quest also told the outlet that a small number of data entries involved dates of birth. Several material details remain undisclosed. The Register says Quest did not say how many customers were affected, how the breach occurred, which third-party service provider was involved, or how far back the exposed records extend. That historical scope matters because Quest has operated for more than 30 years, according to the report. Quest operates more than 120 properties, mostly in Australia, with some in New Zealand and Fiji, The Register reports. The outlet also noted that Quest properties appear on major third-party travel booking sites including Expedia, Wotif, and Booking.com, suggesting overseas visitors who stayed at Quest properties may also be at risk. The company told The Register it has contacted all affected guests, contained and fixed the affected systems, completed remediation, begun forensic investigations, and hired external cybersecurity and privacy advisers. Those steps leave open the operational questions most relevant to customers and partners: how the breach happened, which provider was responsible, and how far back the exposed records extend. For guests, the immediate risk is not limited to spam. Full names combined with email or contact details can support targeted phishing, and the presence of dates of birth in some entries increases the sensitivity of a subset of records. The Register characterizes the information as useful for identity-fraud attempts. This remains a developing cybersecurity incident. The strongest confirmed facts are the existence of the notification, Quest’s attribution to a third-party vulnerability, and the categories of data disclosed so far. The unresolved facts are the size of the incident, the third-party operator involved, and the age and completeness of the database records exposed. Who benefits: External cybersecurity and privacy advisers are already involved, according to Quest’s comment to The Register. The Register says whoever accessed the information is in a position to attempt identity fraud. Who's exposed: Affected Quest guests are exposed to possible identity-fraud attempts, particularly where dates of birth were included. Quest has not named the third-party provider or disclosed the number of affected customers.