Social EngineeringHospitalityRetailPretextingStolen CredentialsCustomer Data InvolvedData ExfiltratedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CHOICE HOTELS INTERNATIONAL INC /DE
bd_0ffa385100f769b7 · schema v1 · pii pii-v1
Full breach record for CHOICE HOTELS INTERNATIONAL INC /DE →On Jan 14, 2026, an external actor used social engineering to bypass MFA and access a Choice Hotels app holding franchisee/applicant records. Access was shut down within an hour. Investigation concluded Jan 26, 2026: names, SSNs, DOBs, and contact info of 66 Maine residents were exposed. Law enforcement notified. Two years of Epiq credit monitoring offered to affected individuals.
Maine clockDiscovered Jan 26, 2026 → Filed with AG Feb 19, 202624d ✓ ME AG ≤30d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_111e43f23c3cd596Indiana State AGfiled 2026-02-19Verified
- bd_13201bac440a62c2New Hampshire State AGfiled 2026-02-19Verified
- bd_bdaaf3841a01cd30Oregon State AGfiled 2026-02-19Verified
- bd_df32201abaf622ccVermont State AGfiled 2026-02-19Verified
Show 2 more filings ↓Show fewer ↑up to 36d gap
- bd_934d91d01e099b7dTexas State AGfiled 2026-02-20(1d gap)Verified
- bd_48ea2a84af5f7055California State AGfiled 2026-01-14(36d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/05cae016-fc3c-489f-b40d-3fa084a2b7c2.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2026
- Raw hash
- c807daeb0ad7fadea37c0c64cc9d9eb6006b986fd1e6e371d2c25fadff33083f
Reporting entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
- Industry
- Other Commercial
Victim entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
- Industry
- Other Commercial
- Industry
- Hospitalitynaics map
Incident
- Discovered
- Jan 26, 2026
- Materiality determined
- —
- Notification sent
- Feb 19, 2026
- Affected individuals
- 66
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- law enforcement notified
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 26, 2026→ Filed with AG: Feb 19, 202624d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.