Skip to main content

Nepal floods: Everest, Annapurna and Manaslu are unaffected and running normally.

How to help
Travel Himalaya Nepal

Breaking · Visas & Entry

Nearly 2 million Quest Apartment guests are being told to replace their passport, here’s what actually happened

A breach at Quest Apartment Hotels exposed passport, licence and card data for 1.99 million guests; some passport numbers should be reissued.

Nearly 2 million Quest Apartment guests are being told to replace their passport, here’s what actually happened
Nearly 2 million Quest Apartment guests are being told to replace their passport, here’s what actually happened

At a glance

Quest Apartment Hotels has told customers swept up in an August data breach to consider replacing their passport, and in some cases their driver’s licence, after the company confirmed the exposure was far larger than first disclosed. A forensic review now puts the number of affected customers at 1,991,613, with passport or licence numbers exposed for 104,268 of them and credit card numbers, some including the CVV security code, exposed for 344,466.

Open vintage atlas showing Spain and Portugal with a Venezuelan passport on top, symbolizing travel.

Key facts

  • Customers affected: 1,991,613, in records dating from before June 2025
  • Passport and/or driver’s licence numbers exposed: 104,268 customers
  • Credit card numbers exposed: 344,466 customers, some including the CVV code
  • Breach identified: 17 August 2026, via a vulnerability in a third-party technology provider
1,991,613customers affected in total
17 Aug 2026breach identified
19 Aug 2026breach first disclosed publicly
< Jun 2025cutoff date of the exposed records

What was actually exposed

Quest says it identified unauthorised access to a database system on 17 August 2026, traced to a vulnerability in a third-party technology provider used across its apartment-hotel network. The company first disclosed the breach publicly on 19 August, but the full scope, the 1.99 million figure, and the fact that passport numbers and credit card CVVs were among the data taken, was only confirmed once the forensic investigation finished, weeks later. No scanned copies of passports or licences were exposed, only the numbers themselves, and the affected records all predate June 2025.

A person typing on a keyboard connected to a laptop showing code, surrounded by wires.
What the Quest breach exposed, by data type
Data typeCustomers affected
Passport and/or driver’s licence numbers104,268
Credit card numbers (with or without CVV)344,466
Total customers in the breach1,991,613

Is your passport still safe to use

Yes, for travel, but you may still want it reissued. The Australian Department of Foreign Affairs and Trade says a compromised passport number “cannot be used to obtain a new passport” and remains valid for international travel on its own. The real risk is identity fraud: a passport number combined with your name, date of birth and address is useful to someone building a false identity, which is why the Australian Passport Office is asking affected customers to contact it directly so it can decide whether to flag or reissue the document.

A hand holding a Russian passport above a travel-themed map, capturing world travel concepts.

What you should actually do right now

Check whether Quest has emailed you directly, the company says it is contacting everyone whose passport, licence or card details were exposed. If your passport number was included, contact the Australian Passport Office, or the passport authority of your own country if you booked from outside Australia, and ask them to assess your record. If a card number was exposed, call your bank’s number on the back of the card, not a number from an email, and ask for a replacement rather than waiting for fraud to show up. Then watch your inbox: breaches this size reliably trigger a wave of phishing emails posing as the company itself, asking you to “verify your details” through a link. Quest will never ask for your full card number or passport number by email.

A business professional holding a coffee cup while checking a smartphone in a corporate setting.

What this means if you are about to travel

It is also a reminder that any operator holding your passport number, a hotel chain, an airline, a trekking company arranging a Nepal permit, carries a version of this same risk. Ask how long they keep your documents, and choose ones who actually apply their security patches.

A close-up shot of Filipino passports at the airport, indicating travel and identity.

What this means for you

If your passport number was in this breach and you already have a trip booked, do not assume a reissue happens overnight, ask the passport office now rather than the week before you fly, since a flagged passport can take longer to clear at the border and a genuine reissue takes weeks. If you are travelling soon regardless, the six-month-validity rule that catches out so many travellers applies here too: check the expiry date while you are already dealing with this, not at check-in. And treat any “Quest Apartment Hotels” email asking you to click a link and confirm card details as fake until you have verified it directly through Quest’s own website.

Cover photo: Evisa Express via Wikimedia Commons (CC BY 2.0). Section photos: Arturo A via Pexels (Pexels licence); cottonbro studio via Pexels (Pexels licence); Tima Miroshnichenko via Pexels (Pexels licence); https://kaboompics.com/ via Pexels (Pexels licence); Kenneth Surillo via Pexels (Pexels licence).

Still running this season

Nepal Classic Tour — 7 Days is running normally

NMA-certified local guides, transparent pricing, 5,000+ treks since 1998. Message us your dates and we'll sort the permits, lodges and logistics — reply within 24 hours, no obligation.

Popular Nepal treks

All treks →
← More Nepal news

Get the free Nepal Trek Insider Guide

Permits, packing, altitude & how to choose your trek — plus a free, no-obligation trip quote, straight to your inbox.

Free trek-planning emails. No spam, unsubscribe anytime.