Breaking · Visas & Entry
Nearly 2 million Quest Apartment guests are being told to replace their passport, here’s what actually happened
A breach at Quest Apartment Hotels exposed passport, licence and card data for 1.99 million guests; some passport numbers should be reissued.

At a glance
- Published
- TopicVisas & Entry
- Verified againstAustralian Passport Office (DFAT)
- Treks coveredNepal Classic Tour — 7 Days
Quest Apartment Hotels has told customers swept up in an August data breach to consider replacing their passport, and in some cases their driver’s licence, after the company confirmed the exposure was far larger than first disclosed. A forensic review now puts the number of affected customers at 1,991,613, with passport or licence numbers exposed for 104,268 of them and credit card numbers, some including the CVV security code, exposed for 344,466.

Key facts
- Customers affected: 1,991,613, in records dating from before June 2025
- Passport and/or driver’s licence numbers exposed: 104,268 customers
- Credit card numbers exposed: 344,466 customers, some including the CVV code
- Breach identified: 17 August 2026, via a vulnerability in a third-party technology provider
What was actually exposed
Quest says it identified unauthorised access to a database system on 17 August 2026, traced to a vulnerability in a third-party technology provider used across its apartment-hotel network. The company first disclosed the breach publicly on 19 August, but the full scope, the 1.99 million figure, and the fact that passport numbers and credit card CVVs were among the data taken, was only confirmed once the forensic investigation finished, weeks later. No scanned copies of passports or licences were exposed, only the numbers themselves, and the affected records all predate June 2025.

| Data type | Customers affected |
|---|---|
| Passport and/or driver’s licence numbers | 104,268 |
| Credit card numbers (with or without CVV) | 344,466 |
| Total customers in the breach | 1,991,613 |
Is your passport still safe to use
Yes, for travel, but you may still want it reissued. The Australian Department of Foreign Affairs and Trade says a compromised passport number “cannot be used to obtain a new passport” and remains valid for international travel on its own. The real risk is identity fraud: a passport number combined with your name, date of birth and address is useful to someone building a false identity, which is why the Australian Passport Office is asking affected customers to contact it directly so it can decide whether to flag or reissue the document.

What you should actually do right now
Check whether Quest has emailed you directly, the company says it is contacting everyone whose passport, licence or card details were exposed. If your passport number was included, contact the Australian Passport Office, or the passport authority of your own country if you booked from outside Australia, and ask them to assess your record. If a card number was exposed, call your bank’s number on the back of the card, not a number from an email, and ask for a replacement rather than waiting for fraud to show up. Then watch your inbox: breaches this size reliably trigger a wave of phishing emails posing as the company itself, asking you to “verify your details” through a link. Quest will never ask for your full card number or passport number by email.

What this means if you are about to travel
It is also a reminder that any operator holding your passport number, a hotel chain, an airline, a trekking company arranging a Nepal permit, carries a version of this same risk. Ask how long they keep your documents, and choose ones who actually apply their security patches.

What this means for you
If your passport number was in this breach and you already have a trip booked, do not assume a reissue happens overnight, ask the passport office now rather than the week before you fly, since a flagged passport can take longer to clear at the border and a genuine reissue takes weeks. If you are travelling soon regardless, the six-month-validity rule that catches out so many travellers applies here too: check the expiry date while you are already dealing with this, not at check-in. And treat any “Quest Apartment Hotels” email asking you to click a link and confirm card details as fake until you have verified it directly through Quest’s own website.
Cover photo: Evisa Express via Wikimedia Commons (CC BY 2.0). Section photos: Arturo A via Pexels (Pexels licence); cottonbro studio via Pexels (Pexels licence); Tima Miroshnichenko via Pexels (Pexels licence); https://kaboompics.com/ via Pexels (Pexels licence); Kenneth Surillo via Pexels (Pexels licence).
Still running this season
Nepal Classic Tour — 7 Days is running normally
NMA-certified local guides, transparent pricing, 5,000+ treks since 1998. Message us your dates and we'll sort the permits, lodges and logistics — reply within 24 hours, no obligation.
Popular Nepal treks
All treks →



































