My News Feed Saturday 1 August 2026

Meriton cyber breach exposes 2000 guests and staff across Australia

• By Editorial Team •
cyber-attackdata-breachhospitalitymeritonprivacycybersecurityaustralia

Guests and employees who have stayed at or worked for serviced apartment giant Meriton across Australia are being warned to remain vigilant after the company disclosed a significant cyber attack targeting its networks.

The breach, which occurred in mid-January, potentially exposed the personal details of almost 2000 people, including guests at Meriton's properties in Sydney, Brisbane, the Gold Coast, Melbourne and Canberra. The company has already notified all affected individuals.

While Meriton has stressed that the incident poses limited risk, the attack underscores growing vulnerabilities in the hospitality sector and raises fresh concerns about how local residents' data is protected when they book accommodation.

According to the company, hackers accessed "incident reports" — documents relating to injuries or incidents that occurred at Meriton properties. Meriton has confirmed that no credit card details, payment information or other sensitive guest data were taken. The company said 35.6GB of data was potentially affected, but stressed "very little was sensitive information."

"There is no evidence that affected individuals have had their information misused, nor that any information has been released into the public realm," Meriton said in a statement.

The company reported the breach to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, as required by law. Meriton has since implemented enhanced security measures and is conducting extensive network monitoring to prevent future attacks.

For guests and staff concerned about their data, experts recommend monitoring their personal information for signs of misuse, remaining cautious of unsolicited contact, and reviewing any communication from Meriton or their banks about suspicious activity.

The Meriton breach is the latest in a disturbing wave of cyber attacks targeting Australian businesses and consumers. Earlier this month, major financial services company Latitude Group revealed that a far more serious breach had exposed the personal details of 14 million Australians and New Zealanders — including millions of driver's licence numbers and passport details. That attack prompted Australia's consumer watchdog to call for urgent action from business leaders to strengthen data protections.

The pattern is stark: in 2022 alone, Australians reported more than $569 million stolen in scams and identity theft — though authorities warn the actual figure is likely several times higher. Major hacks at companies including Medibank and Optus exposed millions of Australians' personal information, eroding public confidence in the safety of corporate data handling.

Industry observers say the frequency and scale of breaches should serve as a warning to hospitality and accommodation providers to treat cybersecurity as a critical priority, not an afterthought. With many Australians relying on online booking platforms and providing personal information to accommodation providers, the stakes for data security have never been higher.

Meriton operates one of Australia's largest networks of serviced apartments, making the breach potentially significant in scope. The company's response — swift notification, engagement with cybersecurity experts, and implementation of new protective measures — follows best-practice protocols, though it comes too late for those whose data has already been compromised.

Reporting compiled from queanbeyanage.com.au, 9news.com.au.

Frequently Asked Questions

How many people were affected by the Meriton cyber attack?

Almost 2000 people were potentially affected, including guests who have stayed at Meriton properties and past and present employees. The company said 1889 individuals have been notified directly about the breach.

What information did hackers access in the breach?

Hackers accessed "incident reports" documenting injuries and incidents that occurred at Meriton properties. No credit card details, payment information, or other sensitive guest data were taken. Meriton said 35.6GB of data was potentially affected, but most was not sensitive.

What should I do if I've stayed at a Meriton property?

Monitor your personal information for signs of misuse and remain cautious of unsolicited contact. If you believe your data has been misused, contact your bank and consider reporting it to the Office of the Australian Information Commissioner. Meriton has notified all affected individuals directly.

More news