CHOICE HOTELS INTERNATIONAL INC /DE
bd_13201bac440a62c2 · schema v1 · pii pii-v1
Full breach record for CHOICE HOTELS INTERNATIONAL INC /DE →Choice Hotels International, Inc. notified the New Hampshire Attorney General of a data security incident occurring on January 14, 2026. An external actor used social engineering (phishing) to bypass multifactor authentication and access an application containing franchisee and applicant records. The breach affected 67 New Hampshire residents, exposing names, Social Security numbers, dates of birth, and contact information. Choice Hotels contained the breach within an hour, notified law enforcement, and began mailing notifications on February 19, 2026, offering two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0ffa385100f769b7Maine State AGfiled 2026-02-19Verified
- bd_111e43f23c3cd596Indiana State AGfiled 2026-02-19Verified
- bd_bdaaf3841a01cd30Oregon State AGfiled 2026-02-19Verified
- bd_df32201abaf622ccVermont State AGfiled 2026-02-19Verified
Show 2 more filings ↓Show fewer ↑up to 36d gap
- bd_934d91d01e099b7dTexas State AGfiled 2026-02-20(1d gap)Verified
- bd_48ea2a84af5f7055California State AGfiled 2026-01-14(36d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/choice-hotels-international-20260219.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2026
- Raw hash
- 609a406cc7a8f2d17b1c1860bd902be72c6c41c3ed61e104821b9fe037a7c352
Reporting entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Victim entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Incident
- Discovered
- Jan 14, 2026
- Materiality determined
- —
- Notification sent
- Feb 19, 2026
- Affected individuals
- 67
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement and is supporting their investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.