Skip to the content
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
LOG IN

What the Quest Apartment Hotels Breach Teaches Us About Supply Chain Security and Data Retention

When Quest Apartment Hotels announced that a cybersecurity incident had affected nearly two million customer records, it brought several critical cybersecurity themes into sharp focus. The breach, which originated from a vulnerability in a third-party service provider, initially appeared to involve basic contact details. However, subsequent forensic analysis revealed that driver licence numbers, passport numbers, and credit card details including sensitive CVV numbers were also compromised.

While any security incident is concerning, examining the details of this situation highlights key trends in modern cyber threats, areas of incremental improvement in data handling, and persistent industry vulnerabilities that businesses must address.

The Growing Risk of Third-Party Supply Chain Vulnerabilities

A central feature of this incident is that the breach occurred through a third-party software provider rather than a direct intrusion into Quest’s primary internal network. This reflects a growing global trend where cybercriminals target third-party vendors and service providers to gain access to secondary networks.

Organisations frequently implement robust security controls within their own network perimeter while inadvertently overlooking the security posture of external suppliers. To reduce supply chain risk, businesses should consider the following measures:

  • Performing thorough cybersecurity audits on all third-party software vendors prior to onboarding.
  • Enforcing strict access controls to limit the amount of customer information external platforms can view or store.
  • Mandating regular security evaluations and compliance attestations from all active software and service providers.

Scanned Copies Versus Document Numbers: A Lesson in Data Minimisation

One notable distinction in this breach is that only document numbers were exposed, rather than scanned images or digital copies of physical identity documents. In previous high-profile corporate breaches, cybercriminals obtained complete scans of passports and driver licences, which significantly increases the risk of fraudulent identity creation.

While the exposure of identity document numbers remains a serious concern that requires affected individuals to replace those numbers, storing document numbers rather than full scanned images is a relative improvement. This demonstrates the practical value of data minimisation. By avoiding the long-term storage of physical document scans, organisations can noticeably reduce the potential severity of a security incident.

Credit Card Storage and PCI DSS Compliance Concerns

A highly concerning element of this breach is the exposure of payment card details, including CVV numbers. The Payment Card Industry Data Security Standard strictly prohibits the retention of CVV details after transaction authorisation.

In the accommodation and hospitality sector, it is common practice to place a temporary hold on a payment card for room bookings. However, retaining full card numbers and CVV codes long-term creates significant financial and reputational risk. Businesses operating in hospitality, retail, and service industries should evaluate their payment handling processes to ensure proper security:

  • Payment systems should utilise secure payment gateways and tokenisation rather than storing raw card details.
  • Sensitive authentication data, such as CVV numbers, must never be saved in persistent storage after card authorisation is completed.
  • Customer payment records should be automatically purged or securely anonymised once transaction processing is finished.

Devaluing Stolen Data Through Proactive Response

When organisations promptly notify affected customers and advise them to replace exposed driver licences, passport numbers, or payment cards, they actively devalue the stolen information. Cybercriminals rely on static, unchanged data to perform fraudulent activities. When document numbers and payment cards are quickly replaced, the usefulness of the breached dataset diminishes rapidly.

To create an environment where cyber attacks are less lucrative, organisations should work towards reducing the overall volume of stored data. Holding less sensitive data and maintaining strict data retention schedules ensures that even if a breach occurs, the information obtained provides minimal value to malicious actors.

Strengthening Your Organisation’s Cybersecurity Posture

The incident involving Quest Apartment Hotels underscores the vital importance of third-party risk management, strict adherence to payment security standards, and proactive data minimisation. As cyber threats continue to evolve, organisations must remain vigilant and continuously refine their technical controls.

Evaluating third-party vendor risks, reviewing data retention schedules, and enforcing strong technical controls are essential steps toward building a resilient security posture.

If you would like to assess your organisation’s third-party risks, review your payment security compliance, or enhance your overall cybersecurity controls, contact the expert team at Vertex Cyber Security today or visit our website for further information.

CATEGORIES

Data Breach

TAGS

data retention - PCI DSS - Quest breach - third party risk - vendor security

SHARE

SUBSCRIBE

PrevPreviousBehind the Scam Call: What the Papua New Guinea Human Trafficking Raid Reveals About Online Fraud

Follow Us!

Facebook Twitter Linkedin Instagram
Cyber Security by Vertex, Sydney Australia

Your partner in Cyber Security.

Terms of Use | Privacy Policy

Accreditations & Certifications

iso27001-certified
blank
iso277001-certified
blank
blank
blank
  • 1300 229 237
  • Suite 10 30 Atchison Street St Leonards NSW 2065
  • 477 Pitt Street Sydney NSW 2000
  • 121 King St, Melbourne VIC 3000
  • Lot Fourteen, North Terrace, Adelaide SA 5000
  • Level 2/315 Brunswick St, Fortitude Valley QLD 4006, Adelaide SA 5000

(c) 2026 Vertex Technologies Pty Ltd (ABN: 67 611 787 029). Vertex is a private company (beneficially owned by the Boyd Family Trust).

download (2)
download (4)

We acknowledge Aboriginal and Torres Strait Islander peoples as the traditional custodians of this land and pay our respects to their Ancestors and Elders, past, present and future. We acknowledge and respect the continuing culture of the Cammeraygal people of the Eora nation and their unique cultural and spiritual relationships to the land, waters and seas.

We acknowledge that sovereignty of this land was never ceded. Always was, always will be Aboriginal land.