QAH A.I CyberSecurity Scoring
QAH
Company Information
Website:http://www.questapartments.com.au
Employees number:613
Number of followers:14,241
NAICS:7211
Industry Type:Hospitality
Homepage:questapartments.com.au
QAH Risk Score (AI oriented)
Between 600 and 649
QAHHospitality
Updated:
22/09/2026
22/09/2026
612/1000
Poor
Caa
QAH Global Score (TPRM)
xxxx
QAHHospitality
Score locked

QAHPoor
Current Score
612Caa (POOR)
01000
2 incidents
-167 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
613
SEPTEMBER 2026
612
AUGUST 2026
776
Breach
17 Aug 2026 • QAH
The Ascott Limited and Quest Apartment Hotels: Quest Apartment Hotels customers' personal data exposed in security breach
Quest Apartment Hotels Data Breach
609
CRITICAL-167
ASCQUE1787106872
Quest Apartment Hotels Investigates Data Breach Impacting Customer Records
Quest Apartment Hotels has confirmed a security breach exposing customers' personal data, including full names, email addresses, and contact details. A limited number of records also contained dates of birth. The incident, detected on 17 August 2026, stemmed from unauthorized access to a database via a vulnerability in a third-party service provider.
The company acted swiftly to contain the breach and secure affected systems, stating the incident has since been resolved. Quest has notified Australia’s Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC). In a customer email, David Mansfield, Managing Director for Australasia at The Ascott Limited (Quest’s parent company), apologized for the breach and assured customers that further updates would be provided if additional risks were identified.
While the exact scale of the breach remains unclear, social media reports indicate affected customers received notifications overnight. Quest operates under The Ascott Limited, which also owns brands like Citadines and Oakwood, with a presence in Australia and globally.
The incident follows Origin Energy’s recent disclosure of a breach affecting 900,000 customers, underscoring ongoing cybersecurity challenges in the region. Quest has advised customers to remain cautious of phishing attempts, particularly unsolicited links or attachments. Further details are pending as the investigation continues.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Breach
17 Aug 2026 • QAH
Quest Apartment Hotels: Quest breach included thousands of credit card CVVs
Quest Apartment Hotels Data Breach Exposes Nearly 2 Million Customers, Including Sensitive Financial and Identification Details
609
CRITICAL-167
QUE1790051572
Quest Apartment Hotels Data Breach Exposes Nearly 2 Million Customers, Including Sensitive Financial and Identification Details
A significant data breach at Quest Apartment Hotels has compromised the personal information of 1,991,613 customers, far exceeding initial estimates. The incident, first disclosed on 19 August 2024, was later revealed to include passport numbers, driver’s licence details, and credit card information some with CVV codes affecting hundreds of thousands of individuals.
### Scope of the Breach
The breach exposed a range of sensitive data:
- 104,268 customers had passport and/or driver’s licence numbers compromised.
- 225,300 vehicle registration numbers were also accessed.
- 46,727 credit card numbers, including CVVs, were stolen posing an immediate fraud risk.
- An additional 297,739 credit cards (without CVVs) were exposed, some of which were expired.
- 271 individuals had NDIS numbers leaked, while 46 had Medicare card details exposed.
The breach originated from a third-party software vulnerability, exploited by an unknown threat actor on 17 August 2024, leading to a website outage. Quest’s forensic analysis confirmed that all exposed data predated June 2025.
### Potential Risks and Expert Concerns
Cybersecurity experts warn that the combination of credit card details (with CVVs), names, and addresses enables immediate online fraud. While passport numbers alone cannot be used to obtain new documents, they can be leveraged in phishing scams when combined with other stolen data.
Despite the severity, no data leaks have been found on the dark web, and no threat actor has claimed responsibility. The lack of a public extortion demand suggests the breach may have been used for payment fraud, identity theft, or intelligence gathering by state actors.
### Quest’s Response
Quest has cooperated with Australian authorities, including the Office of the Australian Information Commissioner (OAIC), Australian Signals Directorate (ASD), Australian Cyber Security Centre (ACSC), and Victoria Police. The company has begun notifying affected customers and implementing cybersecurity improvements to prevent future incidents.
Managing Director David Mansfield issued an apology, acknowledging the breach’s impact and thanking customers for their patience during the investigation. The Department of Foreign Affairs and Trade (DFAT) confirmed that affected passports remain valid for travel, though vigilance against scams is advised.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
776
JUNE 2026
776
MAY 2026
776
APRIL 2026
776
MARCH 2026
776
FEBRUARY 2026
776
JANUARY 2026
776
DECEMBER 2025
776
NOVEMBER 2025
776
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for QAH ??
What was QAH's A.I Rankiteo Cyber Score in September 2026 ??
What was QAH's A.I Rankiteo Cyber Score in August 2026 ??
What was QAH's A.I Rankiteo Cyber Score in July 2026 ??
What was QAH's A.I Rankiteo Cyber Score in June 2026 ??
What was QAH's A.I Rankiteo Cyber Score in May 2026 ??
What was QAH's A.I Rankiteo Cyber Score in April 2026 ??
What was QAH's A.I Rankiteo Cyber Score in March 2026 ??
What was QAH's A.I Rankiteo Cyber Score in February 2026 ??
What was QAH's A.I Rankiteo Cyber Score in January 2026 ??
What was QAH's A.I Rankiteo Cyber Score in December 2025 ??
What was QAH's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on QAH's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with QAH ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view QAH's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?