Skip to content
Back to Blog
low severity February 19, 2026 · 4 min read

Choice Hotels International, Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from Choice Hotels International, Inc., here’s what the filing says was exposed, and what to do about it.

Choice Hotels International, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 19, 2026. The filing puts the incident itself on January 14, 2026.

Choice Hotels International, Inc. Data Breach Notice (Oregon Attorney General)

The filing from Choice Hotels International, Inc. means that personal information belonging to 24,115 people, including Oregon residents, was exposed in an incident on January 14, 2026. The company reported the breach to the Oregon Department of Justice 36 days later on February 19, 2026.

Personal information is now outside the company’s systems

This category covers the core details that identify you as an individual. Once it leaves a company’s control, it cannot be recalled. The record does not list passwords, and the brief confirms none were exposed. That is genuine good news: no one can use this incident to log into your Choice Hotels account or any linked service using stolen credentials from this breach.

What remains exposed retains long-term value. Names combined with dates of birth, addresses, or government identifiers are the raw material for identity theft, fraudulent loan applications, tax fraud, and medical identity schemes. These records do not expire the way a credit card does.

Why the 36-day gap matters

The incident occurred on January 14 and the filing arrived on February 19. That interval is neither unusually fast nor unusually slow under varying state rules. The filing itself contains no discovery date, so it is not possible to know how long the data was accessible before the company became aware of the event. What is certain is that the exposed personal information has been outside the company’s direct control since at least mid-January.

What this exposure enables

With personal information in hand, someone can attempt to open accounts, file taxes under another person’s name, or request replacement identification documents. Because no permanent government or biographic identifiers beyond the broad “personal information” category are specified, the exact risk level for any one individual depends on the precise fields included in their record.

The letter you may receive from Choice Hotels will list the specific data points that applied to you. Absence of a letter usually indicates your information was not part of the affected group, but letters rely on last-known addresses. If you have moved since January 14, 2026, contact the company directly to confirm whether you were included.

The records belong to hotel customers

Choice Hotels holds reservation, loyalty-program, and payment details for millions of guests. The 24,115 individuals named in this filing are people who had stayed at or booked with one of the company’s brands. Their information was collected in the ordinary course of business and is now outside the organisation’s environment.

What cannot be changed

Unlike a compromised password or credit card number, the core personal details listed in this incident cannot be reissued. A date of birth stays the same for life. A home address from the time of the breach remains a verifiable fact about you. This permanence is why such exposures require ongoing vigilance rather than a one-time fix.

How to determine whether this affects you

The company is required to notify affected individuals directly, typically by mail. Watch for a letter from Choice Hotels International. If none arrives, it is likely you were not in the group whose records were exposed. Anyone who has changed address since the January 14 incident should reach out to the company’s customer service to verify their status.

Practical steps that address this specific exposure

  • Place a fraud alert with the three major credit bureaus. This forces lenders to verify your identity before opening new accounts and is the single most effective immediate control.
  • Review your annual credit reports from Equifax, Experian, and TransUnion. Look for accounts or inquiries you do not recognise; the fraud alert makes future monitoring easier.
  • File your taxes early. Submitting before a fraudster can use your details reduces the chance of tax-refund theft.
  • Monitor explanations of benefits from any health insurer. Even though medical information is not explicitly listed, personal details can be used to create fraudulent claims.
  • Be wary of unexpected calls, texts, or emails claiming to be from Choice Hotels, banks, or government agencies. Use known official contact numbers rather than replying to messages that arrive after this disclosure.

The exposure of personal information from 24,115 customers is now a permanent part of your risk profile if you were affected. The absence of credential exposure limits one major avenue of immediate account takeover, but the remaining data keeps its value for years. The letter from the company remains the clearest signal of whether you need to treat this incident as yours. Until it arrives, treat the possibility seriously without assuming the worst.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed February 19, 2026
Last reviewed July 22, 2026
Affected 24115
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email