Choice Hotels International, Inc. was the subject of a data breach notification filed with the TX Attorney General. The AG filing was recorded on February 20, 2026. The breach or discovery date reported in the filing is January 14, 2026.
Data Exposed
Choice Hotels International, Inc. was the subject of a data breach notification filed with the TX Attorney General. The AG filing was recorded on February 20, 2026. The breach or discovery date reported in the filing is January 14, 2026.
Choice Hotels International, Inc. is one of the largest and most successful lodging franchisors in the world, operating thousands of hotels globally under prominent brands like Comfort, Quality Inn, Cambria, and Radisson. Because of its massive footprint in the hospitality and travel sector, the company routinely collects, processes, and stores vast quantities of sensitive information. This includes guest reservation histories, government-issued identification details, home addresses, dates of birth, contact information, and critical financial data such as credit card numbers, billing addresses, and payment card security codes. Additionally, Choice Hotels maintains comprehensive loyalty program databases containing accumulated travel preferences, passport details, and corporate account credentials for millions of frequent travelers. In 2026, Choice Hotels International, Inc. reported a significant cybersecurity incident to the Texas Attorney General, triggering legal scrutiny regarding the security of its enterprise networks and reservation systems. Breaches targeting hospitality and travel giants typically involve sophisticated cyberattacks such as unauthorized access to centralized reservation databases, compromise of third-party booking vendors, or targeted ransomware deployments that exploit vulnerabilities in legacy infrastructure. Because hospitality companies manage decentralized networks connected to countless independently operated franchise properties, threat actors frequently exploit these complex digital ecosystems to infiltrate core servers, siphon customer records, and deploy malicious payloads designed to extract valuable consumer data. The exposure of traveler and loyalty member data in a breach of this magnitude creates severe, long-term risks for affected individuals. Compromised credit card numbers and financial credentials expose victims to immediate fraudulent charges, unauthorized fund transfers, and prolonged banking disputes. Furthermore, the combination of full names, dates of birth, email addresses, and home or passport addresses provides cybercriminals with all the necessary components to execute devastating identity theft, open fraudulent lines of credit, compromise secondary online accounts, and engage in targeted phishing schemes. When travel patterns and loyalty account credentials are leaked, threat actors can also hijack reward points, intercept upcoming travel itineraries, and impersonate victims to access corporate systems. As a major enterprise operating across state lines and serving Texas residents, Choice Hotels International, Inc. had a robust legal obligation to implement and maintain reasonable security measures to protect consumer data. Under the Texas Identity Theft Enforcement and Protection Act, as well as Section 5 of the Federal Trade Commission Act, companies that collect sensitive personal and financial information are legally mandated to deploy adequate administrative, physical, and technical safeguards, including encryption, multi-factor authentication, and routine vulnerability assessments. The occurrence of a data breach of this scale strongly indicates a failure to maintain these mandatory security protocols, leaving consumer networks vulnerable to unauthorized extraction and exploitation. Receiving a data breach notification letter from Choice Hotels International, Inc. serves as formal legal confirmation that your private information was compromised due to corporate negligence. Under modern data privacy jurisprudence, the receipt of such a notice often establishes the requisite legal standing to initiate or join a class action lawsuit, even before fraudulent financial losses materialize, as victims are forced to expend time and resources mitigating ongoing risks. Our law firm is actively investigating potential class action claims on behalf of individuals affected by this breach. We handle all data breach litigation on a strict contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
Based on the data types reported, affected individuals face:
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
What the Texas Identity Theft Enforcement and Protection Act and federal statutes entitle you to recover:
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Texas Identity Theft Enforcement and Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Choice Hotels International, Inc. does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Choice Hotels International, Inc. during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.
Received a notification letter from Choice Hotels International, Inc.?
What it means and what to do next.
Choice Hotels International, Inc. breach?
Free case review · No fee unless you win