Were you recently affected by a data breach?

Accor Data Breach

Accor notified regulators that a third-party service provider’s exposed credentials allowed an unauthorized person to view customer information, including ALL loyalty program data, on July 11 and 12, 2026.

Accor
Date of Breach: July 11-12, 2026
CAU logo

Who was affected:

Clients of Accor

Impacted Data:

Customer information tied to the ALL loyalty program, including passport numbers for at least one reported individual

Accor, the global hospitality group behind the ALL loyalty program, has notified regulators of a security incident tied to a third-party service provider. Anyone with an Accor account should understand what was disclosed.

Accor’s Data Breach Investigation

Accor Management US, Inc., based in New York and part of the French hospitality group Accor SA, filed a notice of a security incident with the New Hampshire Attorney General’s Consumer Protection Bureau. The notice is dated September 29, 2026. According to the filing, the incident did not start inside Accor’s own network. A third-party company that provides services on Accor’s behalf suffered a security incident on its own systems, and that incident exposed login credentials the service provider used to reach certain Accor customer information.

Accor says it learned of the problem on July 11, 2026 and began an investigation right away. The company reports that on July 11 and July 12, 2026, an unauthorized individual used the exposed credentials to view certain customer information, including information connected to the ALL loyalty program. Accor states that the unauthorized activity was limited to whatever those credentials could reach and that no Accor systems were compromised. It also states that ALL loyalty program accounts themselves were not compromised.

In response, Accor says it reset the service provider’s compromised credentials, reset customer account passwords as a precaution, and notified legal authorities outside the United States. On July 17, 2026, the company told customers that it was investigating. After finishing its review, Accor sent follow-up notifications on September 29, 2026 to the individuals it determined were potentially affected.

The filing with New Hampshire reports that approximately one New Hampshire resident was involved and that this person’s passport number was potentially accessed. Accor has not published the total number of people affected across all states and countries, and the sample notification letter attached to the filing leaves the list of affected data elements as a blank merge field rather than spelling it out. For that reason, we cannot say how many people were affected overall or whether every recipient had the same type of information involved. Different recipients may have had different details exposed.

This incident is a reminder that a company’s data security depends on its vendors as well as itself. Hospitality companies rely on many outside providers for marketing, booking, customer service and loyalty program support, and each provider that is given credentials becomes another possible point of entry. When a vendor’s login details are exposed, the people whose records sit behind those logins have no say in how well the vendor protected them.

Passport numbers are among the more sensitive identifiers a company can hold about a customer. Unlike a password, a passport number cannot be changed easily, and it can be combined with a name and date of birth to support identity fraud, to open accounts, or to make a fraudulent identity document appear more convincing. Loyalty program records can also include contact details, travel history and points balances, which scammers can use to craft believable phishing messages about a booking or an account. These are general risks that come with this type of information, not confirmed facts about what happened to any particular person’s data in this incident.

Accor’s notification was sent more than two months after the unauthorized access took place. State data breach laws generally require notice to affected individuals within a set time and in many cases require a report to the Attorney General when residents are affected, which is why this filing appeared on a state regulator’s website. Whether notice was provided in a timely and adequate way for every affected person is the type of question that can be examined if the company’s data security and notification practices are challenged.

We will update this page if Accor or a regulator publishes additional detail, such as the number of people notified or the specific types of information involved. If you received a letter from Accor about this incident, keep it, since it is the best proof that your information was involved.

When Did This Breach Occur?

Accor learned of the incident on July 11, 2026. The company reports that an unauthorized individual used exposed service-provider credentials on July 11 and July 12, 2026. Accor told customers on July 17, 2026 that it was investigating, and it sent follow-up notices to potentially affected individuals on September 29, 2026.

What Information Was Breached?

Accor reports that the information at issue was customer information, including information related to its ALL loyalty program. In the New Hampshire filing, the company states that one resident’s passport number was potentially accessed. The sample notice does not list the data elements for other recipients, and Accor has not publicly disclosed a complete list for everyone affected.

What You Can Do

If you are an Accor customer or ALL loyalty member, consider these steps:

  • Keep the notice you received from Accor, since it shows your information was involved.
  • Change your ALL account password and any other account where you reuse it, and turn on two-step verification where offered.
  • Review your bank and card statements and your loyalty account for activity you do not recognize.
  • Check your credit reports for free at annualcreditreport.com and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
  • Be cautious of emails, calls and texts about your bookings or points, and report suspected identity theft to the Federal Trade Commission and your state Attorney General.

File a Data Breach Lawsuit Against Accor

If you received a notice that your information may have been involved in the Accor data breach, you may be entitled to compensation. Companies that collect customer identifiers such as passport numbers are expected to take reasonable steps to protect them, including steps to make sure their vendors do the same.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 30, 2026 to August 20, 2026
Date of Breach: Reportedly October 1, 2026 (unconfirmed)
Date of Breach: July 11-12, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.