When Quest Apartment Hotels first disclosed a data breach in August, the company described the exposed information as mostly names, email addresses and other contact details. A forensic update a month later revealed a far more serious picture: nearly two million customers affected, including more than 46,000 credit card numbers with their CVVs and over 100,000 passport or driver licence numbers.
The breach originated through a vulnerability in an unnamed third-party service provider, not Quest's own systems, a detail IB Australia flagged in August as central to how cyber underwriters assess supply-chain risk transfer. That question is now sharper: Quest's parent company, The Ascott Limited, confirmed in its September update that 104,268 customers had passport and/or driver licence numbers exposed, 225,300 had vehicle registration numbers affected, and a combined 344,466 credit card numbers were compromised, 46,727 of them with CVVs included.
Vaughan Shanks, chief executive of Melbourne incident response firm Cydarm Technologies, said non-expired card numbers with CVVs were the most immediately harmful data in the breach, since combining them with a name and address makes fraudulent online purchases straightforward. He advised affected customers to cancel exposed cards regardless of whether CVVs were included.
What has not happened is arguably as telling as what has: no threat actor has claimed responsibility, no extortion demand has surfaced, and Information Age found no related listings on the dark web at time of writing. Shanks said that absence points to the data being used quietly "for payment card fraud or identity theft, or by a nation state actor," rather than a typical financially motivated cybercriminal operation.
RMIT cybersecurity associate professor Nalin Arachchilage said a stolen passport number is unlikely to enable identity theft alone but remains valuable because criminals rarely rely on a single data point. Combined with a name and contact details, he said, it can be used to "create highly personalised phishing emails, text messages, or even telephone calls that appear legitimate."
For cyber brokers, the case is worth holding on to for two reasons distinct from the vendor-liability question already raised: initial breach severity assessments can shift dramatically once forensic analysis completes, and the absence of a ransom demand or dark web listing is not itself reassurance, it can just as easily signal a quieter, more calculated threat actor.