Personal information of nearly two million Quest Apartment Hotels customers has been compromised in a data breach, including credit card, passport and Medicare numbers.
Last month, the accommodation provider identified a cyberattack on a database system via a vulnerability in a third-party technology provider.
David Mansfield, the managing director of The Ascott Limited provided an update this week.
Most information related to names and contacts, but also included:.
All the information relates to records from before June 2025.
Mansfield said the company was contacting those affected directly to tell them of which category they were in, the steps they could take, and available support.
Quest said it first identified an outage on its website on 17 August, with investigation revealing "a malicious attack" had exploited a vulnerability in a third-party service provider's software.
Quest said it was cooperating with the Office of the Australian Information Commissioner, the Australian Signals Directorate, the Australian Cyber Security Centre and Victoria Police.
After a data breach involving millions of Optus customers in 2022, the federal government overhauled privacy laws, needing companies to destroy or actively de-identify personal information as soon as it was no longer needed.