The Jerusalem PostIsraeli man reported missing while trekking Greece's Mt. OlympusInquirerBusted Iloilo drug suspect yields P2.8-M methESPNNBA Rank 2026: A new countdown begins with players Nos. 100-51ESPN Deportes¿Cómo van los playoffs al momento?Daily MaverickShinyHunters hackers say they breached FBIGlobal NewsTrump says U.S. to continue buying Canadian potash — but wants cheaper priceLa PresseMark Carney promet de verser 100 millions supplémentaires aux PalestiniensABC NewsAI execs to brief UN Security Council on WednesdayVarietyAll the Top Shows, Movies and Networks in the Merged Paramount-Warner Bros: ‘Yellowstone,’ ‘Harry Potter,’ ‘Mission: Impossible’ and DC Under One RoofDeadlineStreamer Subscription Prices And Tiers – Everything To Know As Costs Rise And Ads AboundSDP EspectáculosRobert Pattinson apunta a su primera nominación al Oscar por PrimetimeSBS 뉴스이 대통령 "북한 존중하고 협력할 것"…평화 공존 방향 제시
The Daily Newsstand · Free, Always
Tuesday, September 22, 2026

Quest tells customers to replace passports after security breach

Translate

Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation revealed additional information had been leaked.

In August, Quest said that it had identified unauthorised access to a database system "from a vulnerability through a third-party service provider".

It advised affected customers that their data from before June 2025, including full names, email addresses and other contact details, had been exposed.

But in new emails and text messages seen by the ABC, Quest told customers an investigation found additional information, including passports, driver's licences, credit card numbers including CVV numbers, and other personal information, had been leaked.

Quest advises reissuing documents 

In an email to a concerned customer seen by the ABC, Quest wrote: 

"If your driver’s licence number was affected, consider contacting your local road authority about obtaining a replacement licence," it said.

"If your passport number was affected, contact the Australian Passport Office (or the relevant issuing authority for non-Australian passports) to discuss whether your passport should be flagged or reissued."

Steven Cooper from NSW was contacted by Quest via text message. 

A text message shown written by Quest informing of a security breach.

This text message was sent to multiple customers. (Supplied)

The text seen by the ABC said: "Our forensic data analysis has confirmed that some additional categories of your personal information were involved in the data security incident we previously notified you about."

Mr Cooper had been a victim of multiple data breaches, including the Origin, Optus and Medibank security leaks, which he said had been frustrating.

"It's pretty annoying to be listed, you know, three or four times," Mr Cooper said.

"The Origin one came, and then the Quest one came quite quickly after,"

he said.

In this breach, he said he was told his information, credit cards, including CVV numbers, car registration and date of birth had been leaked.

Mr Cooper said he stayed with Quest quite often, so he had to change multiple credit card passwords on his joint accounts.

"They said that it's happening even with expired cards. So I guess that's the kind of currency that the hackers are interested in so they can defraud people," he said.

Another customer, who chose to remain anonymous, said they were emailed by Quest informing them that their credit cards and personal information had been leaked. 

They had stayed at Quest Apartments several times and used multiple credit cards, and had to cancel them and have their licence reissued. 

They said the whole process was time-consuming and inconvenient. 

Currently, the waiting time to have your licence reissued and sent to you in the mail, depending on the state, can be up to 14 days.

Getting a passport reissued can take up to six weeks to process according to the Australian Passport Office website.

Information leaked from COVID period

Lizzy, who asked to only use her first name to protect her identity, said she was also advised via text that her information, including her credit card details, was leaked from six years ago during the COVID-19 pandemic.

At the time, she was not able to stay at the Quest apartments due to COVID restrictions, but she said she had booked and paid for the apartment using her credit card.

"It just seems strange that they've still got my credit card details on file, when really, all I did was pay for it online … even though I never ended up staying there and it's been six years," she said.

When she got the first text in August advising that her name and other details had been leaked, she said she didn't "really bother" to worry about it.

"I really just thought that text was a scam, so I didn't really think much of it. I didn't get a follow-up email about it," she said.

It was only when she got a follow-up text last week letting her know her credit card details were also leaked that she started to worry.

David Mansfield, managing director for Australasia at The Ascott Limited, said in a statement that earlier updates advised that: "For the overwhelming majority of impacted individuals, the information identified at that preliminary stage was limited to a combination of name and contact information."

"Our forensic data analysis has now enabled us to determine the specific types of personal information affected."

"I recognise the concern this incident has caused. On behalf of Quest, I sincerely apologise to those who have been affected."

In a statement, Quest said the investigation found information relating to 1,991,613 customers was affected.

It outlined that the following additional information was compromised.

View the original on ABC News (Australia)

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.