My News Feed Saturday 1 August 2026

Meriton cyber attack affects almost 2000 guests and staff in Australia

• By Editorial Team •
cyber attackdata breachidentity theftmeritonhospitalityprivacyfraud

Guests and staff at Meriton serviced apartments across Australia who may have had their personal details caught in a cyber attack earlier this year are being urged to remain vigilant against identity theft and fraud, as the incident highlights growing security risks facing Australian travellers and hospitality workers.

The hotel and apartment giant revealed this week that hackers accessed its systems during a breach in January, potentially exposing the details of almost 2000 guests and employees at its properties in Sydney, Brisbane, the Gold Coast, Melbourne and Canberra.

The company said the stolen data primarily consisted of "incident reports" — documents detailing injuries or accidents that occurred at its serviced apartments — rather than financial information or sensitive guest records. No credit card details were compromised, Meriton confirmed, easing some concerns for affected travellers.

However, the 35.6 gigabytes of information potentially accessed is substantial. Incident reports can contain personal details including names, addresses, dates of stay, employment history, descriptions of injuries, and dates of birth — enough for determined fraudsters to attempt identity theft or targeted financial scams.

Meriton has notified all 1889 potentially affected individuals, mostly current and former guests and employees. The company reported the breach to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner in accordance with privacy legislation.

"There is no evidence that affected individuals have had their information misused, nor that any information has been released into the public realm," Meriton said. The company has implemented enhanced cybersecurity measures and expanded network monitoring to prevent future incidents, while assuring customers of its commitment to data protection.

For residents and employees who stayed or worked at Meriton properties, protecting against identity theft should be a priority. Industry experts recommend monitoring credit reports, watching bank and credit card statements for unauthorised transactions, and remaining alert to unsolicited contact — phone calls, emails or letters — requesting personal information or confirming account details.

The Meriton breach is one of several high-profile cyber attacks affecting Australian organisations and individuals in recent months. Earlier this month, consumer finance company Latitude Group disclosed that hackers had stolen the personal records of 14 million Australian and New Zealand customers, including 7.9 million driver's licence details and 53,000 passport numbers. Last year, major companies including Medibank and Optus suffered comparable data thefts that exposed millions of Australians.

The repeated attacks have prompted warnings from consumer watchdogs, which have urged Australian business leaders to strengthen cybersecurity defences. Identity theft and online financial scams cost Australians more than $569 million in 2022 alone — a figure experts believe represents only about 13 per cent of actual losses, as many victims do not report the crime to authorities.

For Meriton guests and staff, the incident serves as a sobering reminder that even well-known companies can fall victim to determined hackers. Anyone who stayed at or worked for Meriton before January and who has not yet heard from the company should contact it directly to confirm their status and whether they are among those affected.

Reporting compiled from queanbeyanage.com.au, 9news.com.au.

Frequently Asked Questions

What information was stolen in the Meriton cyber attack?

Hackers accessed incident reports detailing injuries and accidents at Meriton serviced apartments. This included guest names, dates of stay, employment details, and descriptions of injuries. No credit card details or sensitive financial information was stolen.

How many people were affected by the breach?

Almost 2000 people, including current and former guests and employees at Meriton properties in Sydney, Brisbane, the Gold Coast, Melbourne and Canberra. The company has notified all affected individuals.

What should people affected by the Meriton breach do?

Monitor your credit reports and bank statements for unauthorised activity. Be alert to unsolicited contact requesting personal information. If you haven't heard from Meriton, contact the company directly to confirm whether you were affected.

More news