AccidentalMisconfigurationData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
CHOICE HOTELS INTERNATIONAL INC /DE
bd_bdb37959843ab45e · schema v1 · pii pii-v1
Full breach record for CHOICE HOTELS INTERNATIONAL INC /DE →Choice Hotels International, Inc. disclosed a data security breach affecting approximately 88,000 individuals between June 1, 2015, and November 12, 2019. A technical misconfiguration involving the Safari web browser caused reservation data—including names, email addresses, and payment card details—to be inadvertently exposed to third-party tracking vendors when the browser crashed. Choice Hotels corrected the code and requested third parties delete the data. No unauthorized access was involved.
California clockDiscovered Nov 12, 2019 → Notified Nov 29, 201917d ✓ CA 60-day OK17 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_7a0f208daa634ba8Oregon State AGfiled 2019-11-29Candidate
- bd_d69bfb5a1239ad62Montana State AGfiled 2019-11-29Verified
- bd_ff0c6471398ec38bWashington State AGfiled 2019-11-29Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-184744
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 29, 2019
- Raw hash
- 35129ced8bf01793e4a074f71f37af28b4dfc7a5cd62ae64878b202bef2f20ef
Reporting entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Victim entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Incident
- Discovered
- Nov 12, 2019
- Materiality determined
- —
- Notification sent
- Nov 29, 2019
- Affected individuals
- 88,000
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 17d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 12, 2019→ Notified: Nov 29, 201917d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.