Social EngineeringPhishingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CHOICE HOTELS INTERNATIONAL INC /DE
bd_df32201abaf622cc · schema v1 · pii pii-v1
Full breach record for CHOICE HOTELS INTERNATIONAL INC /DE →Choice Hotels International, Inc. disclosed a data breach where an external actor used social engineering (phishing) to bypass MFA and gain unauthorized access to an application containing franchisee and applicant records on January 14, 2026. The incident exposed names, contact info, SSNs, and DOBs. Choice Hotels contained the breach within an hour, notified law enforcement, enhanced application access controls, and provided two years of credit monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0ffa385100f769b7Maine State AGfiled 2026-02-19Verified
- bd_111e43f23c3cd596Indiana State AGfiled 2026-02-19Verified
- bd_13201bac440a62c2New Hampshire State AGfiled 2026-02-19Verified
- bd_bdaaf3841a01cd30Oregon State AGfiled 2026-02-19Verified
Show 2 more filings ↓Show fewer ↑up to 36d gap
- bd_934d91d01e099b7dTexas State AGfiled 2026-02-20(1d gap)Verified
- bd_48ea2a84af5f7055California State AGfiled 2026-01-14(36d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-19-choice-hotels-international-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2026
- Raw hash
- c653dfae841cb7cb308dbe888508e944eaae89897c6b4b22fb6b560118f08a68
Reporting entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Victim entity
- Name
- CHOICE HOTELS INTERNATIONAL INC /DEnorm: choice hotels international inc de
- Domain
- choicehotels.com
Incident
- Discovered
- Jan 14, 2026
- Materiality determined
- —
- Notification sent
- Feb 19, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement and is supporting its investigation
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.