Skip to content
>_ITDITDWeb Security Platform

Security Guides

Cards with CVV among the leaked data: what Quest Apartment Hotels guests (including overseas travellers) should do after the 2 million-customer breach

Quest Apartment Hotels in Australia says information on about 1.99 million customers was affected, including 46,727 card numbers with CVVs and 104,268 passport or licence numbers. What guests should do today, per Quest and Australian agencies, and what PCI DSS says about CVVs.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 14 min read

For: anyone who has stayed at a Quest Apartment Hotels property (including business and leisure travellers visiting Australia from overseas), and anyone who handles card data for bookings or services. This article is based on Quest Apartment Hotels' official statements and public material from Australian agencies and the PCI Security Standards Council. It does not cover attack methods.

What guests should do today

1

Check for a notice, and check the sender's domain and number

Quest says it has emailed affected individuals directly and is using SMS or post for people without an email address on file. The notice tells you which of your information was affected. Check your spam folder. Per Quest, genuine emails come from a domain ending in questapartments.com.au, and incident SMS messages come from +61 485 095 177 or +61 468 153 778. Look at the actual sender address, not just the display name.

2

If a card with its CVV was affected, ask your issuer about a replacement

Quest advises reviewing your statements and contacting your bank to report the breach. This site recommends one step further: for unexpired cards, ask about a replacement with a new number. A card number, expiry date and CVV together can be used for online purchases. If your card was issued outside Australia, call the number on the back of the card. If only a number without CVV was affected, keep checking your statements.

3

Don't click 'confirm your booking' links in WhatsApp messages or emails

On September 25, Quest warned of emails and WhatsApp messages impersonating Quest and asking customers to confirm an upcoming booking by clicking a link. Don't click it, don't call the number in the message, and contact the hotel directly using the details on Quest's website. Quest says it will never ask for passwords or card details by SMS (see what is phishing?).

4

Passport numbers: don't rush to replace; check your issuer's advice

Citing the Australian Passport Office, Quest says that if your Australian passport number was compromised, your passport is still safe to use for international travel, and a passport number cannot be used to obtain a new passport. Only the number was affected, not an image of the passport. That advice is about Australian passports. If you hold a passport from another country, follow the OAIC's general advice for exposed identity documents and contact the issuing agency.

5

Australian licence, Medicare or NDIS numbers: contact each agency

Quest's FAQ suggests contacting your state or territory roads authority for a driver licence; Services Australia's Scams and Identity Theft Helpdesk (1800 941 126) for a Medicare number; and the NDIS Fraud Reporting and Scams Helpline (1800 650 717) for an NDIS number, so that a replacement number can be issued if needed.

6

If you have credit in Australia, consider a credit report ban

Quest's FAQ suggests considering a credit report ban, so credit reporting agencies can't disclose your credit file to credit providers without your written consent (it lists how to request one from Equifax and Experian). The OAIC also recommends getting your credit reports when financial information is exposed. This step matters little for visitors who have no Australian credit file.

7

Need help? IDCARE, Scamwatch, cyber.gov.au

IDCARE is Australia's national identity and cyber support service; it assesses your situation and builds a tailored response plan (individuals: 1800 595 160). Scamwatch covers scams and reporting them; cyber.gov.au covers cyber incidents. Quest's FAQ also points to Scamwatch and cyber.gov.au.

① Card number + CVV (46,727)

→ Call your issuer, ask about a replacement, keep checking statements

② Card number only (297,739)

→ Tell your bank, check statements regularly

③ Passport / licence number (104,268)

→ Check the issuer's advice; doubt contacts that quote your number

④ Name and contact details only (most people)

→ Don't click links in "confirm your booking" messages

In every case: no scanned passports or ID documents were affected, per Quest

What to prioritize, by the item named in your notice (organized by this site from Quest's advice and Australian agency guidance).

What happened (from Quest Apartment Hotels' statements)

Everything below is taken from Quest's official statements (August 19, August 21, September 16, September 23 and September 25) and its FAQ.

  1. August 17, 2026

    Quest identifies a website outage; its investigation confirms that a threat actor exploited a vulnerability in a third-party service provider's software and gained access to Quest's environment. The incident is contained.
  2. August 19

    First statement: records from before June 2025, primarily names, email addresses and other contact details.
  3. August 21

    Quest says for the overwhelming majority the information was limited to name and contact details, and that it has notified and is working with the OAIC, the Australian Signals Directorate (ASD), the Australian Cyber Security Centre (ACSC) and Victoria Police.
  4. September 16

    Forensic data analysis completed: approximately 1,991,613 customers affected, with counts per category including card numbers with CVV.
  5. September 23

    Guidance on passport and driver licence numbers; FAQ published.
  6. September 25

    Warning about WhatsApp messages and emails impersonating Quest.
~1,991,613
Customers affected (records from before June 2025)
46,727
Card numbers with CVV (including expired cards)
297,739
Card numbers without CVV (including expired cards)
104,268
Passport / driver licence numbers (numbers only, no images)
Category (Quest's September 16 update)Records
Vehicle registration number225,300
Passport and/or driver licence number (number only, no scanned ID documents)104,268
Credit card number (no CVV, including expired cards)297,739
Credit card number with CVV (including expired cards)46,727
Date of birth3,328
NDIS number (number only)271
Medicare card number (number only)46
What was affected and how Quest responded (per Quest's statements)
Scope
Approximately 1,991,613 customers. Records from before June 2025
Common to affected people
Some combination of name, address, phone number and email address (the FAQ also mentions booking information and personal preferences)
Some people
As in the table above. Not every category applies to every individual
Cause (Quest's account)
A threat actor exploited a vulnerability in a third-party service provider's software and gained access to Quest's environment. Details of the vulnerability have not been disclosed
Quest's response
Contained the incident and completed remediation; investigated with external legal counsel and forensic data analysis specialists; strengthened security controls; required the third-party provider to remediate the affected environment and add security measures
Authorities
Notified and cooperating with the OAIC, ASD, ACSC and Victoria Police

How to read it: 'mostly names and contact details' grew

In August, Quest said the overwhelming majority of affected people had only name and contact details involved. About a month later, with the analysis complete, it published counts that include card numbers with CVVs and passport numbers. It is still true that most people had only names and contact details affected, but if you read the first statement and decided it didn't concern you, check again for a notice. Quest says notifications are going out in stages as it verifies each person's information.

Why were CVVs in a hotel's records? What PCI DSS says

The 3- or 4-digit card verification code (CVV) printed on a card gets special treatment under the card industry security standard PCI DSS. According to public material from the PCI Security Standards Council (PCI SSC), which maintains the standard:

  • Card verification codes are classed as sensitive authentication data (SAD), together with full magnetic-stripe (track) data and PINs.
  • Sensitive authentication data must not be stored after authorization, even if encrypted, and this applies even in environments where no card number is present.
  • Retaining card verification codes after authorization is not permitted even with the customer's permission, and even for card-on-file or recurring transactions. The exception is issuers and companies supporting issuing services with a legitimate business need.
  • PCI DSS does not prohibit collecting the code before the transaction is authorized.

May be stored after authorization (protection requirements apply)

  • Card number (PAN)
  • Cardholder name
  • Expiration date
  • Service code

Not stored after authorization (sensitive authentication data)

  • Card verification codes (CVV etc.)
  • Full track data (magnetic stripe or chip equivalent)
  • PINs and PIN blocks

So what were the 46,727 CVVs in Quest's records? Quest hasn't said. Whether they were captured at booking before authorization, how long they had been kept, and in which system and how they were stored have not been disclosed. Quest's FAQ says the affected records were ones its third-party service provider had left on that environment, and that it is progressing its investigation with the provider. This site is not in a position to conclude from this information that anyone breached PCI DSS.

This site's view: as a guest, what you can do is limit where your CVV goes

The reason PCI SSC gives for banning post-authorization storage is that stolen codes can be correlated with other stolen data to reconstruct both the card number and the verification code. In other words, a CVV is information that should normally be gone once the payment is done, and that it was sitting in booking records is what makes this incident weigh more.

The realistic move for guests is to reduce the people and moments you hand a CVV to: don't write card details into emails or chats with a property; where possible, choose options where payment completes on the spot; and keep a single card for online use, so that when a notice like this arrives, the replacement is limited to one card. For another accommodation-booking incident this year, see the Booking.com reservation data access.

For businesses that handle card data

Quest's own account of the cause goes no further than "a vulnerability through a third-party service provider". What follows is general guidance for anyone taking card details for bookings or services. It is not a statement about the cause of this incident.

1

Find out where CVVs linger, in your systems and your providers'

Not keeping card verification codes after authorization is a principle PCI SSC's FAQs state repeatedly. Check not only your own database but providers' systems, old booking data and copies left over from migrations. As Quest's account shows, records can sit in a provider's environment.

2

Move to payment methods where you never hold card data

If card entry happens entirely on a payment provider's page, neither card numbers nor CVVs reach your side, and there is nothing to leak. It also shrinks your PCI DSS scope.

3

Inventory what providers hold for you, and set deletion deadlines

Quest's affected records were from before June 2025. List what each provider holds for you and until when, and agree in both contract and operations that it is deleted when the deadline passes. The principles are covered in the minimum security baseline for organizations.

Sources (public record)

The facts in this article are based on the public information below. The service provider's name and undisclosed attack methods are not covered.

  • Quest Apartment Hotels, "Statement from Quest Apartment Hotels" (August 19, 2026) — newshub.medianet.com.au
  • Quest Apartment Hotels update page (official statements of August 21 and September 16, the September 23 passport and driver licence statement, the September 25 scam alert, and the FAQ) — questapartments.com.au/update
  • PCI Security Standards Council FAQ 1280, "Can card verification codes/values be stored for card-on-file or recurring transactions?" — pcisecuritystandards.org
  • PCI SSC FAQ 1533, "Why is storage of sensitive authentication data (SAD) after authorization not permitted even when there are no PANs in an environment?" — pcisecuritystandards.org
  • PCI SSC glossary, "Sensitive Authentication Data" and "Cardholder Data" — SAD / CHD
  • Office of the Australian Information Commissioner (OAIC), "Respond to a data breach notification" — oaic.gov.au
  • IDCARE — idcare.org / Scamwatch — scamwatch.gov.au / ASD's Australian Cyber Security Centre — cyber.gov.au

Update history

2026-09-30: First version, based on Quest Apartment Hotels' statements and FAQ from August 19 to September 25, 2026, and public material from PCI SSC, the OAIC and others. Quest's investigation is continuing; we will update this if it publishes more.

FAQ

QWhat was exposed in the Quest Apartment Hotels breach?
A

According to Quest's September 16, 2026 update, information on approximately 1,991,613 customers was affected, all from records before June 2025. Contact information (some combination of name, address, phone number and email) was affected, and depending on the person: vehicle registration number (225,300), passport and/or driver licence number (104,268; the number only, no scanned ID documents), credit card number without CVV (297,739), credit card number with CVV (46,727), date of birth (3,328), NDIS number (271) and Medicare card number (46). The card figures include expired cards.

QHow do I know if I'm affected?
A

Quest says it emailed affected individuals directly and is contacting those without an email address by SMS or post. Check your spam folder. Quest says its emails come from a domain ending in questapartments.com.au, and SMS messages about the incident come from +61 485 095 177 or +61 468 153 778. Its FAQ says that if you don't hear from Quest soon, your information was not affected.

QI was told my card number and CVV were affected. What should I do?
A

Quest advises reviewing your statements and contacting your bank to report the breach. This site recommends going one step further for unexpired cards: call your card issuer and ask about a replacement card with a new number, since a card number, expiry date and CVV together can be used for online purchases. For a card issued outside Australia, call the number on the back of your card.

QIs a hotel allowed to store CVVs?
A

The PCI Security Standards Council, which maintains the card industry standard PCI DSS, classifies card verification codes as sensitive authentication data and says they must not be stored after authorization, even if encrypted. Quest has not said why CVVs were present in its records or at what point the data was captured. This site is not in a position to judge Quest's compliance and reports only what Quest has stated.

QMy passport number was exposed. Should I replace my passport?
A

Quest, citing the Australian Passport Office, says that if your Australian passport number was compromised, your passport is still safe to use for international travel, and a passport number cannot be used to obtain a new passport. That advice concerns Australian passports. For passports from other countries, follow the OAIC's general advice and contact the issuing agency.

QI got a WhatsApp message or email from 'Quest'.
A

On September 25, 2026, Quest warned of unsolicited emails and WhatsApp messages impersonating Quest and asking customers to confirm an upcoming booking by clicking a link. It says not to click the link or call the number in the message, and to contact the hotel directly using the details on Quest's website.

QWhat caused it?
A

Quest says a threat actor exploited a vulnerability in a third-party service provider's software and gained access to Quest's environment, which it found while investigating a website outage on August 17. Details of the vulnerability have not been disclosed.