logo

Australian hotel chain leaks guests’ PII after breach at third-party database operator

ID: aa401af6-50a9-581d-ba05-179a12fff63a

STIX ID: report--aa401af6-50a9-581d-ba05-179a12fff63a

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

...
...

Quest, an Australian aparthotel chain operating over 120 properties, disclosed that on 17 August 2026 an unauthorized party accessed a database via a third‑party service provider vulnerability, exposing guest PII (full names, email/contact details and some dates of birth for records before June 2025). The company says it has contained and remediated the systems, notified affected guests and engaged external cybersecurity and privacy advisers, but has not identified the third party or the number/range of impacted customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.