Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Abstract orange shield with keyhole representing cyber security for hospitality venues

Quest Guest Data Leaked Through a Supplier — What Venues Must Do

One of Australia’s biggest aparthotel operators has just shown how guest data leaks even when your own front desk does everything right. Quest — which runs more than 120 serviced-apartment properties across Australia, New Zealand and Fiji — has emailed guests to say their personal information was exposed. The breach didn’t happen at reception. It happened at a third-party service provider Quest had trusted with the data.

Quest identified unauthorised access on 17 August 2026. The exposed records include guests’ full names, email and contact details, and in some cases dates of birth — data going back to before June 2025.

Why this should worry every venue

The part every hospitality operator should sit up for isn’t the hotel — it’s the supplier. Quest didn’t get breached at the front desk; a company it handed guest data to did. And that’s exactly where the risk usually hides. In the venues we look after around Sydney and the Northern Beaches, guest data is almost never in one place. It’s spread across your PMS, booking engine, channel manager, Wi-Fi captive portal, email marketing tool and loyalty app. Most operators we onboard genuinely can’t name every third party holding a copy of their guest list.

Under the Australian Privacy Act you stay accountable for guest data even when a supplier loses it. “Our vendor did it” is not a defence the OAIC accepts.

What to do this week

  • Map the flow. List every system and integration that touches your booking or POS data — that is your real exposure, not just your own server.
  • Interrogate your suppliers. Ask each one what guest data they store and how it’s protected, and get the answer in writing.
  • Delete what you don’t need. Quest’s leaked records pre-dated June 2025 — data it had little reason to still hold. Set a retention limit and enforce it.
  • Lock the doors. Turn on multi-factor authentication everywhere, and make sure your breach plan names who notifies the OAIC.

None of this needs to be a big project. We help Australian venues map their guest-data supply chain, tighten third-party access and get properly breach-ready. It usually starts with a single afternoon working out who actually holds your guest list — and if you can’t answer that today, that’s the place to start.

Not sure who holds your guest data?

All IT Services helps hospitality venues across Sydney, the Northern Beaches and Central West NSW secure their booking, POS and guest systems.

Written by Dan Briggs, All IT Services. General information only — not specific security advice for your business.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →