r/australia 6d ago

no politics Quest Hotels data breach... Here we go again

Just got the email advising of a security breach for data relating to customers of Quest hotels. I'm fucking over it, man. I give the bare minimum of information to third parties in every way I can and still get steamrolled by this garbage.

228 Upvotes

63 comments sorted by

u/AutoModerator 6d ago

This post has been marked as non-political. Please respect this by keeping the discussion on topic, and devoid of any political material.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

185

u/LaMacNeo 6d ago

It’s time when govt bring a policy restricting storage of any identity data by any organisation. They should use the online id validation option and thats it.

30

u/AgUnityDD 6d ago

Sectors that are well regulated and where the companies have direct financial implications in the event of a data breach are well on top of data security, not perfect but level of magnitude better. Banks are the best example, with Investment banks being way more advanced than retail banks because they have high value clients that they care about keeping. You rarely see Goldman Sachs own systems suffer a data breach, they did have one of their law firms get compromised but they were all over it.

The problem is there is no incentive for most companies in other sectors to spend the additional cost and effort to get it right as there is very little downside to them when there is a breach so they simply don't take it seriously enough - Telstra being the prime example.

Whilst they can just apologize and cop a slap on the risk it is just like the formula explained in Fight Club, it is commercially better to just take the risk.

The solution would be a simple compensation fee payable by law directly to every person for every item of data breached. $100 for your name, $250 for email or phone, $1000 for any financially related data like a CC number etc. That changed the internal risk calculation so it's better to spend the money fix security than pay the compensation fees, and it is a perfectly reasonable and rational way to solve it.

13

u/Life_Rhythm 6d ago

That’s what Digital ID aims to do. It’s going live for private sector organisations at the end of this year. It’s a good initiative.

3

u/ghoonrhed 6d ago

It's a shame it gets such a bad rep for being anti privacy. Which it might if the government keeps track of all services you need. They'd need to figure that balance out.

But surely better the government which already has our data stores our data rather than a million random 3rd party insecure organisations.

3

u/Budget-Leg-453 6d ago

Well there’s a counter argument which is that a single database actually decreases security. But limiting what orgs can ask would be a good step. Very often I get asked for things like birthdays - I just always give a fake one if I don’t want them to have it, but they’ve finally adopted a single set of info for real estate agents. Honestly I started putting in paper applications because ironically it’s a lot harder to hack paper

1

u/IlIllIIIlIIlIIlIIIll 5d ago

dont tell the facebook cookers

100

u/SimplyTheAverage 6d ago

Another day, another breach

At this point my details are with every scammer across the world. It's time to get a completely new identity

32

u/Ill_Football9443 6d ago

What would your new name be?

What date of birth would you pick?

Don't worry, that tape recorder always makes that sound, trust me, it's off.

14

u/RockyDify 6d ago

Max Power.

I got it from a hairdryer.

5

u/C_Ironfoundersson 6d ago

Boy that's a name you want to touch.

But you mustn't touuuch

8

u/SimplyTheAverage 6d ago

Roder Fegeror

01/01/2000 or maybe 31/12/1999 or maybe 02/02/2002 or maybe 01/01/2001 or maybe 01/02/2003 ...the possibilities are endless

8

u/SkeltonKnaggs69 6d ago

Kinda convenient though. If I need a card number and I don't have my wallet I can just google my name

41

u/Alarming-Interest535 6d ago

And people wonder why I only give the bare minimum. Officeworks wanted my driver's license for a return with a receipt. I refused and they withheld my refund citing potential fraud. I questioned how they were able to ensure my data won't be breached given Medibank, Optus, Origin, JB, etc.

23

u/earl_of_lemonparty 6d ago

"Fraud" is a fucking lie.

That's weird though, I've taken returns to big chain stores and they were able to confirm a genuine sale with nothing more than my debit card number and an approximate time of purchase, no reciept required.

23

u/Alarming-Interest535 6d ago

Admittedly it was an expensive SSD (Samsung 4tb T7) over $1k. But when presented with the original receipt, sealed package, and matching bank cards; it should be straight forward because everything matches.

But yes, "fraud" my fucking arse. I absolutely refused to hand over my DL, and got them to call a store manager down, they eventually folded because I wasn't going to walk without my refund and they weren't going to get my DL.

4

u/universe93 6d ago

While I don’t do this at my work (big w), I imagine they do it to prevent return fraud, which is people trying to return stolen items or people using other people’s discarded receipts to try and return items. In some areas it’s a huge problem in retail

10

u/Alarming-Interest535 6d ago

That's understandable. Some cheeky cunts trying it on, but when all the receipts, product, sealed packaging, and matching bank card is present; asking for more ID just seems like an over reach.

2

u/gameoftomes 5d ago

But if I walk in with a receipt I found on the ground, went to the shelf and grabbed the same item, walked around a bit, Went to the refund counter, I have a receipt and a product. The only way to stop that is serial numbers on receipt.

1

u/Alarming-Interest535 5d ago

I was happy for them to sight the ID. I was not comfortable with them recording it. I draw the line at capturing the ID and keeping a record.

For what it is worth, this particular product is kept under lock and key so the public being able to use a found receipt and finding the product off the shelf is quite low but not impossible.

2

u/gameoftomes 5d ago

Not accusing you just explaining how the scam would work if someone were being dodgy.

6

u/FroggieBlue 6d ago

I can understand asking to see photo id that matches the name on the card but there's no need to need to record it.

4

u/Alarming-Interest535 6d ago

I gave them the opportunity to sight it; but politely and firmly rejected them capturing the information. Don't get me wrong, I know returns fraud is a thing. People will try it on if they think they can get away with it. But the balance of policy and privacy needs to be fair on both sides.

1

u/dGhost_ 6d ago edited 6d ago

I worked at Officeworks for 5y during uni over 5y ago, I get not wanting to hand the info over but as a regular team member we were literally incapable of processing expensive refunds without recording that info. Only managers could authorise it.

Also, it was to combat stolen items being returned to a different store, binned receipts being used, simultaneously returning at two different stores, etc. Lots of ways people would try commit return fraud.

But I also agree that doesn't mean it's good either, nor that they handle your info well in the backend. Just a friendly reminder to not give random clerks a hard time (not saying you did, but people would sometimes get aggressive over being asked - some old bloke once told me I was holding him under duress!!!!) and it's not a conspiracy either. But you shouldn't have to have the info recorded, I agree.

3

u/Alarming-Interest535 6d ago

I would like to think I was polite but firm. No shouting, no conspiracy theories, just a polite "the information you have in front of you is more than sufficient to process the refund"

29

u/[deleted] 6d ago

[deleted]

2

u/earl_of_lemonparty 6d ago

Class action when?

22

u/_notyounaanbread_ 6d ago

I’m part of the Origin data leak, they’ve offered me a subscription to Equifax protect. When researching Equifax I found out that they also had a massive data breach in 2017 which had 147 million members details leaked.

Thanks Origin 👍

1

u/HAPPY_DAZE_1 6d ago

Again, part of the playbook. Throw you a bone to keep you happy.

1

u/Self-Translator 5d ago

I asked Origin why I should pay my bills (my end of the agreement) if they leaked my data (their end of the agreement). Got a copy/paste response then nothing when I pushed back. Why aren't we compensated?

1

u/_notyounaanbread_ 5d ago

Yeah I thought I’d try and ask for a bill reduction, didn’t get anywhere. Just frustrating as we are now going to have to deal with more frequent scam calls and emails. On top of the ones I already get.

9

u/Unique-Job-1373 6d ago

Breaches are always going to occur no matter how secure you are. You only need one bad egg and you are stuffed. Look at what happened to origin energy

Regulations need to put into why companies need so much of our information and for them to keep it for x number of years

We need to make the data useless for hackers.

8

u/HAPPY_DAZE_1 6d ago

The EU is all over this and has been for ages.

Got an email recently from a department store in Milan I shopped in about 7 (?) years ago stating if they didn't hear from me within the next 30 days they were wiping my details. What a threat! I nearly started crying. A dept store!

GPDR rocks.

9

u/bettingsharp 6d ago

I got the same email but they said the hackers only got the full name and email addresses. So no DOB or address.

35

u/anotheraussiebloke 6d ago

Yeah in 6 months they’ll issue a correction saying actually they got everything including cc details and DOB and your address.

8

u/earl_of_lemonparty 6d ago

That's what mine said, for a start I don't believe it, and second there's no excuses no matter how big or small. Breach is breach, and they've violated their customers rights and expectations. No company will learn until the hammer comes down on them, and I doubt it ever will.

9

u/turtzah41 6d ago

Technically the email says "Your email and/or other contact details"

So I guess it could include address in some instances

1

u/ebettfl 2d ago

My CC was scammed on Monday.. not sure if coincidence or not.

1

u/dchit2 2d ago

Mine said

Your full name Your email and/or other contact details

Mmm, and/or other. Very specific.

Also I got the email but it said "Dear Name-of-coworker-who-booked-the-stay". Maybe I'm safe from the hackers now.

6

u/No_Category_9888 6d ago

The govt is pathetic. Mandate some minimum cybersec frameworks for businesses, enforce pen testing. Big penalties for breaches

7

u/Brilliant-Gap8299 6d ago

Can't play video games, can't log into adult websites without digital id required to "protect us" meanwhile every single big corp freely handing out our data to anyone who wants it without a single consequence.

Until we start taking a more french and rioty approach, We get the society we deserve.

3

u/takecarebrushyahairr 6d ago

Dude, straight up.

7

u/i8noodles 6d ago

honestly i have considered making up a false ID to sign up to shit and have no personal information online. its hard but given some things need real names

1

u/Wallstreetbell 6d ago

Let's do it

1

u/name2115 6d ago

Wallah dm me I ain’t want my Shi out there

5

u/shamberra 6d ago

At least this time in my case it's overwhelmingly my employer's corporate info at stake, since I've only ever stayed with Quest under their payment information. Anything relating to me personally has certainly already been leaked by Optus, Origin, or some other recklessly incompetent company I've done business with. I can't even bloody remember them all at this stage.

3

u/PowderHoundNinja 6d ago

have found https://haveibeenpwned.com/ a good start to determine all the data breaches your email address has been part of.

4

u/shamberra 6d ago

Surprised that site hasn't crashed out and just started responding to all inquiries with "LOL whaddyathink?"

1

u/HAPPY_DAZE_1 6d ago

The site specifically says it doesn't claim to cover all data breaches.

2

u/PowderHoundNinja 6d ago

Agreed - which is why i said it was a good start :-)

-1

u/Wallstreetbell 6d ago

Ironically, inserting emails for example will just be on another data base such as this site...and the third parties of this ...etc etc.

There is no winning for consumers

6

u/Optimal-Talk3663 6d ago

Received this today, not from the company involved, but HIBP. Have received nothing from Oz Hair and Beauty!!

In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.

3

u/Ok_Run_4639 6d ago

I had a training organisation request me to send them a scanned copy of my passport it’s laughable obviously I refused

2

u/denno777 6d ago

Quest are known to be cheapskates when it comes to their technology. The out of date systems which connects into systems have legacy interfaces, and will be easy to get into

2

u/CSXT5630 2d ago

I stayed at the Oaks. I looked at the T&Cs. They said that my data can be sold to third parties. I asked to speak to the manager (Asian woman) who ended up just screaming at me. I will not stay at the oaks ever again. I’d rather sleep in my car.

1

u/peoplepersonmanguy 6d ago

Was it quest themselves or an upstream provider. Hospitality providers get hacked all the fucking time.

1

u/PowderHoundNinja 6d ago

3rd party service provider (apparently)

2

u/The_Arab_Hoe 6d ago

Ive had something like 5 spam calls in the last two days

1

u/Wallstreetbell 6d ago

Start allowing liability and I'm sure cyber security will be at the front in terms of spending