# Quest breach update identifies payment and identity-document exposure

_Published Tuesday, September 22, 2026 at 11:17 AM EDT · Security · Latest · Tier 2 — Notable_

![Quest breach update identifies payment and identity-document exposure — Primary](https://cdn-res.keymedia.com/cms/images/us/026/0270_639256759975789259.jpg)

A forensic update on the Quest Apartment Hotels breach found nearly two million affected customers, expanding the incident beyond the contact information emphasized in August. Parent company The Ascott Limited said 344,466 credit card numbers were compromised, including 46,727 with CVVs, while 104,268 customers had passport or driver-licence numbers exposed and 225,300 had vehicle registration numbers affected.

The intrusion originated through a vulnerability at an unnamed third-party provider rather than Quest's systems. No attacker, extortion demand or related dark-web listing had been identified when the report was published.

## Sources

- [Insurance Business America](https://www.insurancebusinessmag.com/au/news/cyber/quests-breach-was-mostly-names-and-emails--a-month-later-its-more-590653.aspx)

---
Canonical: https://techandbusiness.org/newswire/xPYt7FQkKSnf7m41HtoMzN
Published: 2026-09-22T15:17:03.415Z
Story chronology: 2026-09-22T12:13:31.000Z
Retrieved: 2026-09-22T17:43:36.458Z
Publisher: Tech & Business (techandbusiness.org)
