Accor, the global hospitality group behind the ALL loyalty program, has notified regulators of a security incident tied to a third-party service provider. Anyone with an Accor account should understand what was disclosed.
Accor’s Data Breach Investigation
Accor Management US, Inc., based in New York and part of the French hospitality group Accor SA, filed a notice of a security incident with the New Hampshire Attorney General’s Consumer Protection Bureau. The notice is dated September 29, 2026. According to the filing, the incident did not start inside Accor’s own network. A third-party company that provides services on Accor’s behalf suffered a security incident on its own systems, and that incident exposed login credentials the service provider used to reach certain Accor customer information.
Accor says it learned of the problem on July 11, 2026 and began an investigation right away. The company reports that on July 11 and July 12, 2026, an unauthorized individual used the exposed credentials to view certain customer information, including information connected to the ALL loyalty program. Accor states that the unauthorized activity was limited to whatever those credentials could reach and that no Accor systems were compromised. It also states that ALL loyalty program accounts themselves were not compromised.
In response, Accor says it reset the service provider’s compromised credentials, reset customer account passwords as a precaution, and notified legal authorities outside the United States. On July 17, 2026, the company told customers that it was investigating. After finishing its review, Accor sent follow-up notifications on September 29, 2026 to the individuals it determined were potentially affected.
The filing with New Hampshire reports that approximately one New Hampshire resident was involved and that this person’s passport number was potentially accessed. Accor has not published the total number of people affected across all states and countries, and the sample notification letter attached to the filing leaves the list of affected data elements as a blank merge field rather than spelling it out. For that reason, we cannot say how many people were affected overall or whether every recipient had the same type of information involved. Different recipients may have had different details exposed.
This incident is a reminder that a company’s data security depends on its vendors as well as itself. Hospitality companies rely on many outside providers for marketing, booking, customer service and loyalty program support, and each provider that is given credentials becomes another possible point of entry. When a vendor’s login details are exposed, the people whose records sit behind those logins have no say in how well the vendor protected them.
Passport numbers are among the more sensitive identifiers a company can hold about a customer. Unlike a password, a passport number cannot be changed easily, and it can be combined with a name and date of birth to support identity fraud, to open accounts, or to make a fraudulent identity document appear more convincing. Loyalty program records can also include contact details, travel history and points balances, which scammers can use to craft believable phishing messages about a booking or an account. These are general risks that come with this type of information, not confirmed facts about what happened to any particular person’s data in this incident.
Accor’s notification was sent more than two months after the unauthorized access took place. State data breach laws generally require notice to affected individuals within a set time and in many cases require a report to the Attorney General when residents are affected, which is why this filing appeared on a state regulator’s website. Whether notice was provided in a timely and adequate way for every affected person is the type of question that can be examined if the company’s data security and notification practices are challenged.
We will update this page if Accor or a regulator publishes additional detail, such as the number of people notified or the specific types of information involved. If you received a letter from Accor about this incident, keep it, since it is the best proof that your information was involved.
When Did This Breach Occur?
Accor learned of the incident on July 11, 2026. The company reports that an unauthorized individual used exposed service-provider credentials on July 11 and July 12, 2026. Accor told customers on July 17, 2026 that it was investigating, and it sent follow-up notices to potentially affected individuals on September 29, 2026.
What Information Was Breached?
Accor reports that the information at issue was customer information, including information related to its ALL loyalty program. In the New Hampshire filing, the company states that one resident’s passport number was potentially accessed. The sample notice does not list the data elements for other recipients, and Accor has not publicly disclosed a complete list for everyone affected.
What You Can Do
If you are an Accor customer or ALL loyalty member, consider these steps:
- Keep the notice you received from Accor, since it shows your information was involved.
- Change your ALL account password and any other account where you reuse it, and turn on two-step verification where offered.
- Review your bank and card statements and your loyalty account for activity you do not recognize.
- Check your credit reports for free at annualcreditreport.com and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Be cautious of emails, calls and texts about your bookings or points, and report suspected identity theft to the Federal Trade Commission and your state Attorney General.
File a Data Breach Lawsuit Against Accor
If you received a notice that your information may have been involved in the Accor data breach, you may be entitled to compensation. Companies that collect customer identifiers such as passport numbers are expected to take reasonable steps to protect them, including steps to make sure their vendors do the same.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.