Were you recently affected by a data breach?

National Corporate Housing Data Breach

National Corporate Housing notified individuals on August 7, 2026 that a physical break-in at a Denver storage location exposed personal information contained in paper HR records.

National Corporate Housing
Date of Breach: The incident likely occurred between January 1, 2026 and May 19, 2026, and was discovered on May 19, 2026. Affected individuals were notified beginning August 7, 2026.
CAU logo

Who was affected:

Clients of National Corporate Housing

Impacted Data:

Name, address, Social Security number, driver’s license number, and date of birth

National Corporate Housing, a company that provides furnished corporate housing and relocation services for traveling professionals, government employees, and military personnel, recently notified individuals that a physical security breach at one of its storage locations may have exposed some of their personal information. The company says it is not aware of any misuse of the affected information, but is providing notice out of caution.

Companies that maintain personal information in any form, whether digital or physical, are expected to secure that information with reasonable safeguards, including proper physical access controls over paper records.

National Corporate Housing’s Data Breach Investigation

According to the notice sent to affected individuals, National Corporate Housing discovered on May 19, 2026 that an unauthorized actor had entered a locked storage room at the company’s Denver location and accessed and removed paper records containing certain HR files that included personal information. The company states that the incident likely occurred sometime between January 1, 2026 and May 19, 2026, indicating the exact date the physical intrusion took place is not precisely known, only the outer window during which it could have happened.

Unlike many data breaches involving hacking or phishing of digital systems, this incident involved a physical security failure, specifically unauthorized entry into a locked room used to store paper HR files. National Corporate Housing reported the incident to the Greenwood Village Police Department on the same day it was discovered, and the company states that notification to affected individuals was not delayed at the request of law enforcement.

Physical breaches of stored paper records are less common than digital intrusions but carry many of the same risks once personal information is removed by an unauthorized party, since the underlying data, such as Social Security numbers and dates of birth, does not lose its sensitivity simply because it was on paper rather than in a database. Physical storage rooms and file archives are sometimes overlooked in security planning relative to network-facing systems, even though many companies, including those with large distributed workforces like National Corporate Housing, still maintain substantial volumes of paper HR and employment records on-site.

Following the discovery, National Corporate Housing states it launched an in-depth investigation to determine the scope of the incident and identify potentially affected individuals, working with its human resources team and engaging third-party experts. The company also says it has taken steps to revisit its access control measures for stored files to help prevent a similar incident from occurring again.

National Corporate Housing is offering complimentary access to identity monitoring, fraud consultation, and identity theft restoration services, along with 24 months of Experian IdentityWorks credit monitoring, to individuals affected by this incident.

State data breach notification laws generally apply to unauthorized access of personal information regardless of whether the underlying records are stored digitally or on paper, and Massachusetts, where this notice was filed, requires notice without unreasonable delay once a company determines that residents’ personal information was compromised. The roughly three-month gap between discovery of the incident on May 19, 2026 and the August 7, 2026 notification letters reflects the time typically needed to determine which specific individuals’ files were affected, particularly when the exact date of the underlying intrusion within a multi-month window is not precisely known.

Physical records containing HR information, such as Social Security numbers, dates of birth, and driver’s license numbers, remain a valuable target for identity thieves even though this type of breach doesn’t involve hacking, malware, or a compromised computer network. An unauthorized individual who physically removes paper files can potentially retain and misuse that information indefinitely, in the same way stolen digital data can be misused, which is why companies typically offer extended credit monitoring and identity restoration services in these cases rather than treating a physical breach as lower-risk than a cyber intrusion.

Businesses that maintain large volumes of employee or client records, including companies that operate across many locations like National Corporate Housing, face a particular challenge in maintaining consistent physical security controls, such as locked storage rooms and access logging, across every site. This incident illustrates how a gap in physical access controls at even a single location can expose sensitive personal information just as significantly as a digital data breach would.

When Did This Breach Occur?

National Corporate Housing states the physical intrusion likely occurred sometime between January 1, 2026 and May 19, 2026, and was discovered on May 19, 2026, the same day it was reported to local police. Notification letters to affected individuals are dated August 7, 2026.

What Information Was Breached?

According to the notice, the exposed paper HR files may have included each affected individual’s name, address, Social Security number, driver’s license number, and date of birth. National Corporate Housing states that no financial account, credit card, or debit card information was involved in this incident.

What You Can Do

If you received a data breach notification letter from National Corporate Housing, consider taking the following steps to protect yourself:

  • Enroll in the complimentary 24-month Experian IdentityWorks credit monitoring and identity restoration services referenced in your notice.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus, given that Social Security numbers and driver’s license numbers were involved.
  • Monitor your credit reports for new accounts opened without your authorization.
  • Be alert to phishing attempts or unsolicited contact referencing this incident.
  • Contact Experian’s customer care team with any questions about activating your identity restoration services.

File a Data Breach Lawsuit Against National Corporate Housing

Companies that maintain personal information, whether in digital systems or physical paper files, are expected to secure that information against unauthorized access. When physical security measures fail and sensitive records like Social Security numbers and driver’s license numbers are exposed, the people affected can face a lasting risk of identity theft and fraud through no fault of their own.

If you received a breach notification letter from National Corporate Housing, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: The incident likely occurred between January 1, 2026 and May 19, 2026, and was discovered on May 19, 2026. Affected individuals were notified beginning August 7, 2026.
Date of Breach: The incident occurred on April 9, 2026. Affected individuals were notified beginning August 7, 2026.
Date of Breach: The incident was identified on July 9, 2026. Affected individuals were notified beginning August 7, 2026.
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.