Breaking
RUIran has put forward conditions for opening the Strait of HormuzFRAn English speaker in police custody in Paris for rape and sexual assault on childrenBRPRF saves man after two cardiorespiratory arrests on BR-365RUFuel tanks exploded in the Obolonsky district of KyivFRDonald Trump's speech at the UN on September 22, 2026: national achievements and position towards IranBRBus belonging to pilgrims falls into a cliff in Cruzeiro (SP) after mechanical problemITMacron at the UN: defense of multilateralism, priority to the Strait of Hormuz and appeals on Gaza, Ukraine and the ICCGLOBALTrump's White House Helipad Event Highlights Press Pool Boycott and Constitutional ConcernsRUUS Secretary of State Marco Rubio and other officials attend Trump's meeting with Zelensky at the UN General AssemblyTRGamze Durmuş Pakkan will referee the FC Slovan Liberec-Rosenborg BK match in the UEFA Women's European Cup 2nd qualifying round.RUIran has put forward conditions for opening the Strait of HormuzFRAn English speaker in police custody in Paris for rape and sexual assault on childrenBRPRF saves man after two cardiorespiratory arrests on BR-365RUFuel tanks exploded in the Obolonsky district of KyivFRDonald Trump's speech at the UN on September 22, 2026: national achievements and position towards IranBRBus belonging to pilgrims falls into a cliff in Cruzeiro (SP) after mechanical problemITMacron at the UN: defense of multilateralism, priority to the Strait of Hormuz and appeals on Gaza, Ukraine and the ICCGLOBALTrump's White House Helipad Event Highlights Press Pool Boycott and Constitutional ConcernsRUUS Secretary of State Marco Rubio and other officials attend Trump's meeting with Zelensky at the UN General AssemblyTRGamze Durmuş Pakkan will referee the FC Slovan Liberec-Rosenborg BK match in the UEFA Women's European Cup 2nd qualifying round.
BackQuest Apartments advises customers to replace passports and licences after data breach reveals additional leaked information
Quest Apartments advises customers to replace passports and licences after data breach reveals additional leaked information
Developing
ABC Top Stories58 minutes agoTech2 min readAustralia

Quest Apartments advises customers to replace passports and licences after data breach reveals additional leaked information

Quick Look

  • Quest Apartments has advised customers affected by an August data breach to replace passports and driver's licences after discovering additional leaked information including credit card numbers with CVV, passport details, and car registration.
  • The breach impacted 1,991,613 customers, with data from before June 2025 exposed, including information from bookings made during the COVID-19 pandemic.
  • Affected customers report frustration and inconvenience, with reissuance times up to six weeks for passports and 14 days for licences.

AI-generated summary

Why It Matters

Quest Apartments initially reported in August that unauthorised access to a database system occurred via a vulnerability in a third-party service provider, exposing customer data from before June 2025 including names, email addresses, and contact details. A subsequent investigation revealed additional sensitive information had been leaked.

Font size

Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation revealed additional information had been leaked.

In August, Quest said that it had identified unauthorised access to a database system "from a vulnerability through a third-party service provider".

It advised affected customers that their data from before June 2025, including full names, email addresses and other contact details, had been exposed.

But in new emails and text messages seen by the ABC, Quest told customers an investigation found additional information, including passports, driver's licences, credit card numbers including CVV numbers, and other personal information, had been leaked.

Quest advises reissuing documents

In an email to a concerned customer seen by the ABC, Quest wrote:

"If your driver’s licence number was affected, consider contacting your local road authority about obtaining a replacement licence," it said.

"If your passport number was affected, contact the Australian Passport Office (or the relevant issuing authority for non-Australian passports) to discuss whether your passport should be flagged or reissued."

Steven Cooper from NSW was contacted by Quest via text message.

The text seen by the ABC said: "Our forensic data analysis has confirmed that some additional categories of your personal information were involved in the data security incident we previously notified you about."

Mr Cooper had been a victim of multiple data breaches, including the Origin, Optus and Medibank security leaks, which he said had been frustrating.

"It's pretty annoying to be listed, you know, three or four times," Mr Cooper said.

In this breach, he said he was told his information, credit cards, including CVV numbers, car registration and date of birth had been leaked.

Mr Cooper said he stayed with Quest quite often, so he had to change multiple credit card passwords on his joint accounts.

"They said that it's happening even with expired cards. So I guess that's the kind of currency that the hackers are interested in so they can defraud people," he said.

Another customer, who chose to remain anonymous, said they were emailed by Quest informing them that their credit cards and personal information had been leaked.

They had stayed at Quest Apartments several times and used multiple credit cards, and had to cancel them and have their licence reissued.

They said the whole process was time-consuming and inconvenient.

Currently, the waiting time to have your licence reissued and sent to you in the mail, depending on the state, can be up to 14 days.

Getting a passport reissued can take up to six weeks to process according to the Australian Passport Office website.

Information leaked from COVID period

Lizzy, who asked to only use her first name to protect her identity, said she was also advised via text that her information, including her credit card details, was leaked from six years ago during the COVID-19 pandemic.

At the time, she was not able to stay at the Quest apartments due to COVID restrictions, but she said she had booked and paid for the apartment using her credit card.

"It just seems strange that they've still got my credit card details on file, when really, all I did was pay for it online … even though I never ended up staying there and it's been six years," she said.

When she got the first text in August advising that her name and other details had been leaked, she said she didn't "really bother" to worry about it.

"I really just thought that text was a scam, so I didn't really think much of it. I didn't get a follow-up email about it," she said.

It was only when she got a follow-up text last week letting her know her credit card details were also leaked that she started to worry.

David Mansfield, managing director for Australasia at The Ascott Limited, said in a statement that earlier updates advised that: "For the overwhelming majority of impacted individuals, the information identified at that preliminary stage was limited to a combination of name and contact information."

"Our forensic data analysis has now enabled us to determine the specific types of personal information affected."

"I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected."

In a statement, Quest said the investigation found information relating to 1,991,613 customers was affected.

It outlined that the following additional information was compromised.

What to Watch

AI outlook — possibilities, not facts

  • Quest Apartments will face increased scrutiny from Australian privacy regulators regarding its data handling practices.

    Likely · Within weeks

  • Affected customers will experience a rise in phishing attempts and identity theft-related fraud in the coming months.

    Possible · Within months

Open Questions

  • What specific third-party service provider was responsible for the vulnerability?
  • Has Quest Apartments implemented additional security measures to prevent future breaches?
  • Are there any regulatory investigations or penalties related to this data breach?
  • How long were the compromised data stored on Quest's systems after the COVID-19 pandemic period?

Related Topics

This article was originally published by ABC Top Stories.

Related Stories

Gig workers earn money recording household chores to train robots
Developing·

Gig workers earn money recording household chores to train robots

Mohamad Dunggio, a 23-year-old from Gorontalo in Indonesia, earns $3 to $10 per hour recording himself doing household tasks like dishwashing and cooking with a phone mounted on his head to provide egocentric training data for robotics. Thousands of gig workers globally supply such data to companies including Appen, which collects up to 60,000 hours of video monthly from contributors worldwide. While workers say the work provides income and new skills, concerns remain about pay, privacy, data commoditization, and withdrawal fees. Experts note robots still struggle with real-world home variability despite advances in demonstrations.

ABC Top Stories
2 min read
More on this topicquest apartments