Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CHOICE HOTELS INTERNATIONAL INC /DE
bd_48ea2a84af5f7055 · schema v1 · pii pii-v1
Full breach record for CHOICE HOTELS INTERNATIONAL INC /DE →Choice Hotels International, Inc. reported a data breach on January 14, 2026, where an external actor used social engineering to bypass multifactor authentication and access an application containing franchisee and applicant records. The incident involved names and Social Security numbers. Access was shut down within an hour. The company notified law enforcement and is offering two years of credit monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0ffa385100f769b7Maine State AGfiled 2026-02-19(36d gap)Verified
- bd_111e43f23c3cd596Indiana State AGfiled 2026-02-19(36d gap)Verified
- bd_13201bac440a62c2New Hampshire State AGfiled 2026-02-19(36d gap)Verified
- bd_bdaaf3841a01cd30Oregon State AGfiled 2026-02-19(36d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 37d gap
- bd_df32201abaf622ccVermont State AGfiled 2026-02-19(36d gap)Verified
- bd_934d91d01e099b7dTexas State AGfiled 2026-02-20(37d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619003
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2026
- Raw hash
- 9e77bd03cafc0af3af6695067fe855727c9a56516932745130dad1f90e7ef813
Reporting entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Victim entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Incident
- Discovered
- Jan 14, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.