Quest Guest Data Leaked Through a Supplier — What Venues Must Do
One of Australia’s biggest aparthotel operators has just shown how guest data leaks even when your own front desk does everything right. Quest — which runs more than 120 serviced-apartment properties across Australia, New Zealand and Fiji — has emailed guests to say their personal information was exposed. The breach didn’t happen at reception. It happened at a third-party service provider Quest had trusted with the data.
Why this should worry every venue
The part every hospitality operator should sit up for isn’t the hotel — it’s the supplier. Quest didn’t get breached at the front desk; a company it handed guest data to did. And that’s exactly where the risk usually hides. In the venues we look after around Sydney and the Northern Beaches, guest data is almost never in one place. It’s spread across your PMS, booking engine, channel manager, Wi-Fi captive portal, email marketing tool and loyalty app. Most operators we onboard genuinely can’t name every third party holding a copy of their guest list.
What to do this week
- Map the flow. List every system and integration that touches your booking or POS data — that is your real exposure, not just your own server.
- Interrogate your suppliers. Ask each one what guest data they store and how it’s protected, and get the answer in writing.
- Delete what you don’t need. Quest’s leaked records pre-dated June 2025 — data it had little reason to still hold. Set a retention limit and enforce it.
- Lock the doors. Turn on multi-factor authentication everywhere, and make sure your breach plan names who notifies the OAIC.
None of this needs to be a big project. We help Australian venues map their guest-data supply chain, tighten third-party access and get properly breach-ready. It usually starts with a single afternoon working out who actually holds your guest list — and if you can’t answer that today, that’s the place to start.
Not sure who holds your guest data?
All IT Services helps hospitality venues across Sydney, the Northern Beaches and Central West NSW secure their booking, POS and guest systems.
Source
- The Register — Australian hotel chain leaks guests’ PII after breach at third-party database operator (19 August 2026)
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
