Quest Apartment Hotels issued customer security notifications confirming unauthorized access to a database system via a vulnerability in a third-party service provider. The exposed records pre-date June 2025 and primarily comprise customer names, email addresses, street locations, and contact metadata, with a subset of entries containing dates of birth across more than 1.5 million records. Quest confirmed that password credentials, credit card details, financial transactions, and passport numbers were not stored in the compromised repository and remained uncompromised. Quest isolated the affected systems, completed technical remediation work, and notified privacy regulators.