LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Choice Hotels International, Inc. Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

Choice Hotels International, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·February 19, 2026
Choice Hotels International, Inc. Data Breach Notice (Oregon Attorney General)

Occurred January 14, 2026 · publicly disclosed February 19, 2026. Approximately 24115 people affected.

MEDIUM
Severity
24115
People affected
1
Data types exposed
February 19, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Choice Hotels International, Inc. disclosed a data breach on February 19, 2026 that affected 24,115 individuals and exposed personal information. Anyone who received a notice from the company or whose data may have been involved should review the full notice and take recommended steps to protect their information.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
24115 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Choice Hotels International, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 19, 2026. The filing places the incident itself on January 14, 2026, and states that 24,115 people were affected. Public detail describes the exposed material as personal information per the breach notification; further specifics on method, full scope, or exact data fields remain limited in the disclosed record.

For guests, loyalty members, and others whose information a major hotel company may hold, a notice of this kind matters because personal data can be reused for fraud or account abuse long after the initial event. What is known so far comes from the Oregon Attorney General filing rather than a fuller public technical report.

Inside the incident

According to the Oregon Department of Justice filing dated February 19, 2026, Choice Hotels International, Inc. reported a data breach affecting 24,115 people. The company placed the incident on January 14, 2026. The notice characterizes the exposed material as personal information. The public filing does not describe how the incident was discovered, what systems were involved, whether ransomware or another intrusion method was used, or how long unauthorized access may have lasted. No threat actor is named in the disclosed record, and no dollar figures, file names, or technical indicators appear in the facts available here.

The notice was directed at least in part to Oregon residents, which is consistent with state breach-notification requirements when residents’ personal information is involved. Whether the same event affected people in other states, and in what numbers, is not detailed in the Oregon filing summary provided. Timing between the stated incident date and the February reporting date is a matter of record; the reasons for that interval are not explained in the available facts.

How a breach like this happens

Incidents that lead to hotel-industry breach notices often follow familiar patterns, though none of these should be read as a confirmed description of this specific case. Attackers commonly gain an initial foothold through stolen or guessed remote-access credentials, phishing that tricks an employee into handing over login details, unpatched software on internet-facing systems, or compromised accounts at a vendor that connects to the company’s network. Once inside, they may move laterally to systems that store guest profiles, reservation records, or loyalty data, then copy information for later use or sale.

In other cases, a misconfigured cloud storage bucket, an exposed database, or a third-party booking or payment partner becomes the weak point without a dramatic “break-in.” Detection can lag if logging is incomplete or if the activity blends with normal traffic. Organizations then investigate, determine what was accessed, and issue notices when state law thresholds are met. Because no intrusion method is attributed in the Choice Hotels filing summarized here, these points remain general background only.

About Choice Hotels International, Inc.

Choice Hotels International, Inc. is a large hospitality company that franchises and supports well-known hotel brands used by leisure and business travelers. Companies in this sector typically maintain reservation systems, guest contact details, loyalty and rewards programs, and related customer-service records. They may also handle payment-related information at booking or check-in, though card data is often processed through specialized payment channels rather than stored long-term in the same place as marketing or profile data.

A breach notice from such an organization is consequential because hotel brands sit at the intersection of travel planning, identity verification at the front desk, and ongoing marketing relationships. Even when only a subset of records is involved, the combination of names, contact details, and stay-related information can be useful to criminals who craft targeted scams or attempt account takeovers elsewhere. The Oregon filing establishes that tens of thousands of people were included in this notification; it does not, by itself, map every brand, property, or system that may have been touched.

What data was at risk

The breach notification names the exposed material as personal information. It does not list individual data elements such as Social Security numbers, driver’s license numbers, full payment card numbers, dates of birth, or loyalty account credentials in the facts provided. Exact contents therefore remain unconfirmed beyond that broad label.

Organizations of this kind commonly hold names, postal and email addresses, phone numbers, reservation and stay history, and loyalty identifiers. Some also retain government ID details for certain bookings or corporate travel arrangements. None of those categories should be treated as confirmed exposures in this incident unless a fuller notice or regulator update says so. Readers who received a letter from the company should rely on the specific data types listed in their individual notice.

What's at stake

For affected individuals, the practical risks include phishing and social-engineering attempts that reference a real stay or loyalty account, attempts to reset passwords on other services using recovered email addresses, and, if richer identity data were involved, new-account or credit fraud. Even limited personal information can make fraudulent messages more convincing. Monitoring financial and email accounts for unexpected activity is a proportionate response when a hotel-related notice arrives.

For the organization, consequences can include regulatory follow-up, notification and support costs, reputational strain with guests and franchisees, and the operational burden of investigation and remediation. None of those outcomes is quantified in the Oregon filing facts given here, and fault or negligence is not established by the mere existence of a notice.

What to do if you're exposed

If you received a breach notice from Choice Hotels International, Inc., or if you believe you may be among the 24,115 people referenced in the Oregon filing, start with the steps in the letter itself, including any fraud-monitoring offer or reference number. Change passwords on related accounts, especially email and loyalty logins, and enable multi-factor authentication where available. Watch bank and credit-card statements for unfamiliar charges and consider a fraud alert with the major credit bureaus if your notice indicates sensitive identity data. Be wary of unsolicited calls or messages that claim to be from the hotel brand and ask for passwords, payment details, or remote access.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you prioritize further password changes and monitoring. Keep records of any notice you receive and of steps you take; if new official updates appear from the company or regulators, compare them carefully with what you were originally told rather than relying on rumor.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyChoice Hotels International, Inc. security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Choice Hotels International, Inc.’s full breach history →
RelatedMore incidents at Choice Hotels International, Inc.

More recent breaches

ASOS US Sales LLC Data Breach Notice (Oregon Attorney General)September 9, 2026BestCare treatment Services, Inc. Data Breach Notice (Oregon Attorney General)September 8, 2026Boston Health Care for the Homeless Program Data Breach Notice (Oregon Attorney General)September 3, 2026American Addiction Centers Data Breach Notice (Oregon Attorney General)September 3, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Choice Hotels International, Inc. Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram