Support
Contact
Book a Free ReviewCall 1300 053 948
Cybersecurity

1.5 million records via a supplier: why a third party's breach is your problem

An Australian hotel group's guest data was exposed through a third-party provider. Why supply-chain breaches are surging, and how to reduce your exposure.

An Australian hotel group's guest data was exposed last month — not through its own systems, but through a third-party provider's. Your suppliers' security is now your problem, and this post is about what to do with that fact.

In August 2026, Quest Apartment Hotels publicly disclosed a data breach traced to a vulnerability at a third-party service provider, detected on 17 August. Reports put the exposure at roughly 1.5 million guest records — names, email addresses, home addresses and, for some guests, dates of birth. Quest's own booking systems weren't the way in; a supplier's were. That detail is the story. For every business that hands customer data to booking engines, payroll providers, marketing platforms and industry software vendors — which is every business — the breach you have to plan for may not happen on your network at all.

Why are supply-chain breaches surging?

Because attackers follow economics. Breaking into one supplier can yield the data of hundreds of that supplier's customers — a far better return than attacking those customers one at a time. Several of the largest Australian breaches of the past few years have followed exactly this pattern: the victim organisation's name is on the headline, but the way in was a vendor, a contractor's login, or a piece of shared software. Regulators have noticed too — the OAIC's breach reporting has repeatedly flagged third-party and supply-chain incidents as a growing share of notifications.

"But it was our supplier's fault" doesn't work

Legally and commercially, the data you collected is yours to protect, wherever it sits. If your customers' details leak from your booking platform or your marketing tool, the Notifiable Data Breaches scheme looks to you, your customers blame you, and your name is on the apology email. Outsourcing the processing does not outsource the accountability. That sounds harsh, but it points at the fix: you can't control a supplier's security, but you can control which suppliers you use, what you give them, and how fast you find out when something goes wrong.

Five things you can actually control

Know where your data lives.

Most businesses cannot list the third parties holding their customer data. Build the list — every platform, every integration, every agency with a login. You cannot manage exposure you haven't mapped.

Give suppliers less.

Data a supplier never holds cannot leak from them. Question every field you sync: does the marketing platform really need dates of birth? Does the booking engine need to keep records forever?

Ask suppliers hard questions before you sign.

Where is data stored, who can access it, do they hold recognised security certifications, what is their breach-notification commitment to you — in hours, not "as required by law"?

Limit what a supplier's compromise can reach.

Vendor logins and integrations should have the minimum access that makes them work, with multi-factor authentication and monitoring — so a breached supplier is a contained problem, not a skeleton key. This is core managed cybersecurity work.

Watch for the downstream wave.

After a breach like this, the stolen data gets used: phishing emails referencing real bookings, fake "verify your details" messages, credential-stuffing against your systems. Our in-house 24/7 SOC watches for exactly this follow-on activity.

Hospitality and retail should pay particular attention

Accommodation, hospitality and retail run on exactly the kind of third-party stack this incident came through — booking engines, channel managers, POS platforms, loyalty systems — and hold exactly the kind of guest and customer data attackers resell. If that's your industry, our retail & hospitality page covers how we secure that stack, and continuous vulnerability scanning covers the internet-facing systems the attackers probe first.

FAQ

Frequently asked questions

If our supplier is breached, do we have to notify anyone?

Quite possibly. If personal information you collected is involved and serious harm is likely, the Notifiable Data Breaches scheme applies to you as well as the supplier — the obligation follows the data, not the network it leaked from. Get advice early; the assessment clock is short.

What should we ask a supplier after they disclose a breach?

Exactly what data of yours was involved, over what period, whether it was encrypted, what the attacker did with it, what they've fixed, and what they will fund (such as customer notification). Put the answers in writing.

We're a small business — can we really vet big software vendors?

You won't change a global vendor's security, but you still choose what to give them and what to switch on. Data minimisation and locked-down integrations are decisions you own at any size — and they're free.

How do we find out early that a supplier issue is affecting us?

Monitoring your own environment for unusual activity — strange logins, odd data flows from integrations — catches many supplier compromises before the supplier's own disclosure arrives. That's a core reason our SOC watches client environments around the clock.

The next step

Start with the map: one page listing every third party that holds your customer data, and what they hold. If you'd like help building it — and closing the gaps it reveals — call 1300 053 948 or start with our managed cybersecurity page.

Book your free IT & Cyber Security Review

See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.