Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Quest Apartment Hotels

Quest Apartment Hotels Vendor Cyber Rating & Cyber Score

questapartments.com.au

Making corporate stay effortless at more than 160 locations across Australia, New Zealand and Fiji. For over 35 years, Quest has provided convenient locations, reliable standards and flexible living conditions for extended stay corporate travellers among Australia’s top 500 companies. Quest is now one of the top 15 apartment hotel providers in the world and is widely recognised as the market leader of apartment hotel accommodation in Australia.


QAH A.I CyberSecurity Scoring

QAH
Company Information
Website:http://www.questapartments.com.au
Employees number:613
Number of followers:14,241
NAICS:7211
Industry Type:Hospitality
Homepage:questapartments.com.au
QAH Risk Score (AI oriented)
Between 600 and 649
logo
QAHHospitality
Updated:
22/09/2026
612/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
QAH Global Score (TPRM)
xxxx
logo
QAHHospitality
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

QAHPoor
Current Score
612Caa (POOR)
01000
2 incidents
-167 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
613Before Incident
SEPTEMBER 2026
612Before Incident
AUGUST 2026
776Before Incident
Breach
17 Aug 2026 • QAH
The Ascott Limited and Quest Apartment Hotels: Quest Apartment Hotels customers' personal data exposed in security breach

Quest Apartment Hotels Data Breach

609After Incident
CRITICAL-167
ASCQUE1787106872
Quest Apartment Hotels Investigates Data Breach Impacting Customer Records Quest Apartment Hotels has confirmed a security breach exposing customers' personal data, including full names, email addresses, and contact details. A limited number of records also contained dates of birth. The incident, detected on 17 August 2026, stemmed from unauthorized access to a database via a vulnerability in a third-party service provider. The company acted swiftly to contain the breach and secure affected systems, stating the incident has since been resolved. Quest has notified Australia’s Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC). In a customer email, David Mansfield, Managing Director for Australasia at The Ascott Limited (Quest’s parent company), apologized for the breach and assured customers that further updates would be provided if additional risks were identified. While the exact scale of the breach remains unclear, social media reports indicate affected customers received notifications overnight. Quest operates under The Ascott Limited, which also owns brands like Citadines and Oakwood, with a presence in Australia and globally. The incident follows Origin Energy’s recent disclosure of a breach affecting 900,000 customers, underscoring ongoing cybersecurity challenges in the region. Quest has advised customers to remain cautious of phishing attempts, particularly unsolicited links or attachments. Further details are pending as the investigation continues.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal data (full names, email addresses, contact details, dates of birth)Systems Affected: DatabaseIdentity Theft Risk: High
DATA BREACH
Full namesEmail addressesContact detailsDates of birthSensitivity Of Data: HighPersonally Identifiable Information: Yes
Breach
17 Aug 2026 • QAH
Quest Apartment Hotels: Quest breach included thousands of credit card CVVs

Quest Apartment Hotels Data Breach Exposes Nearly 2 Million Customers, Including Sensitive Financial and Identification Details

609After Incident
CRITICAL-167
QUE1790051572
Quest Apartment Hotels Data Breach Exposes Nearly 2 Million Customers, Including Sensitive Financial and Identification Details A significant data breach at Quest Apartment Hotels has compromised the personal information of 1,991,613 customers, far exceeding initial estimates. The incident, first disclosed on 19 August 2024, was later revealed to include passport numbers, driver’s licence details, and credit card information some with CVV codes affecting hundreds of thousands of individuals. ### Scope of the Breach The breach exposed a range of sensitive data: - 104,268 customers had passport and/or driver’s licence numbers compromised. - 225,300 vehicle registration numbers were also accessed. - 46,727 credit card numbers, including CVVs, were stolen posing an immediate fraud risk. - An additional 297,739 credit cards (without CVVs) were exposed, some of which were expired. - 271 individuals had NDIS numbers leaked, while 46 had Medicare card details exposed. The breach originated from a third-party software vulnerability, exploited by an unknown threat actor on 17 August 2024, leading to a website outage. Quest’s forensic analysis confirmed that all exposed data predated June 2025. ### Potential Risks and Expert Concerns Cybersecurity experts warn that the combination of credit card details (with CVVs), names, and addresses enables immediate online fraud. While passport numbers alone cannot be used to obtain new documents, they can be leveraged in phishing scams when combined with other stolen data. Despite the severity, no data leaks have been found on the dark web, and no threat actor has claimed responsibility. The lack of a public extortion demand suggests the breach may have been used for payment fraud, identity theft, or intelligence gathering by state actors. ### Quest’s Response Quest has cooperated with Australian authorities, including the Office of the Australian Information Commissioner (OAIC), Australian Signals Directorate (ASD), Australian Cyber Security Centre (ACSC), and Victoria Police. The company has begun notifying affected customers and implementing cybersecurity improvements to prevent future incidents. Managing Director David Mansfield issued an apology, acknowledging the breach’s impact and thanking customers for their patience during the investigation. The Department of Foreign Affairs and Trade (DFAT) confirmed that affected passports remain valid for travel, though vigilance against scams is advised.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Payment fraudIdentity theftIntelligence gathering
IMPACT
Data Compromised: 1,991,613 customer records, including passport numbers, driver’s licence details, credit card information (with and without CVVs), vehicle registration numbers, NDIS numbers, and Medicare card detailsSystems Affected: Website (third-party software)Downtime: Website outageBrand Reputation Impact: SignificantIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Passport numbersDriver’s licence detailsCredit card information (with and without CVVs)Vehicle registration numbersNDIS numbersMedicare card detailsNumber Of Records Exposed: 1,991,613Sensitivity Of Data: HighPersonally Identifiable Information: Yes
JULY 2026
776Before Incident
JUNE 2026
776Before Incident
MAY 2026
776Before Incident
APRIL 2026
776Before Incident
MARCH 2026
776Before Incident
FEBRUARY 2026
776Before Incident
JANUARY 2026
776Before Incident
DECEMBER 2025
776Before Incident
NOVEMBER 2025
776Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for QAH ?
?
What was QAH's A.I Rankiteo Cyber Score in September 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in August 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in July 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in June 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in May 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in April 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in March 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in February 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in January 2026 ?
?
What was QAH's A.I Rankiteo Cyber Score in December 2025 ?
?
What was QAH's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on QAH's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with QAH ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view QAH's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?