In July 2026, Accor discovered that stolen vendor credentials let an unauthorized person view ALL loyalty program customer data, including at least one guest’s passport number. Accor sent follow-up notices in September 2026, but the total number of people affected has not been publicly disclosed. If you received a notice, keep it, freeze your credit, and watch for phishing attempts referencing your Accor bookings.
| Company | Accor Management US, Inc. |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | ALL loyalty program account information, Passport number, Customer profile and contact details |
| People Affected | Not Publicly Disclosed |
| Attack Method | Third-Party Vendor Breach |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewAccor Management US, Inc., the North American arm of the global hotel and hospitality group, has disclosed a data security incident affecting customers of its ALL loyalty program. The company recently notified a state regulator that someone outside the organization viewed loyalty account data without permission. The Accor data breach involved stolen vendor login credentials rather than a direct attack on Accor’s own network.
What Happened in the Accor Management US, Inc. Data Breach?
According to a filing made with a state attorney general’s office, Accor learned of the problem in July 2026. The company says a third-party service provider it relies on for certain customer-facing functions suffered its own security incident. That separate incident exposed login credentials the vendor used to access specific Accor customer records.
Accor reports that an unauthorized individual used those exposed credentials on July 11 and July 12, 2026. During that window, the person reportedly viewed certain customer information connected to the ALL loyalty program. Accor states the access was limited to whatever the vendor’s credentials could reach. The company also says its own internal systems were not compromised and that loyalty accounts themselves were not broken into directly.
Once Accor discovered the issue, it says it moved to reset the vendor’s compromised credentials. As a precaution, the company also reset customer account passwords. Accor reports that it alerted legal authorities outside the United States as part of its response.
The timeline laid out in the regulatory filing shows a gap between discovery and full notification. Accor told customers on July 17, 2026 that an investigation was underway. However, the company did not send detailed follow-up letters to affected individuals until September 2026, after it finished reviewing what had happened.
Who was affected?
The people affected by this incident are Accor customers who are enrolled in, or otherwise connected to, the ALL loyalty program. Because loyalty programs often span many countries, this likely includes travelers across multiple regions, not just a single market.
Accor has not publicly disclosed the total number of individuals affected worldwide. The state filing that prompted this disclosure covers only one resident of that state. As a result, the full scope of the breach, including whether employees or only guests were involved, has not been publicly disclosed.
It is also unclear whether every affected person had the same categories of information exposed. The sample notice attached to the regulatory filing left the specific data fields blank for individual recipients. This means some customers may have had more sensitive information involved than others.
What Information Was Potentially Exposed?
Accor’s filing describes the exposed information as customer data tied to the ALL loyalty program. For at least one confirmed individual, this included a passport number. Because the notice template did not spell out every data element for all recipients, other customers may have experienced a different mix of exposed information.
- ALL loyalty program account information
- Passport number (confirmed for at least one individual)
- Possible additional customer contact or profile details tied to loyalty accounts
A passport number is a particularly sensitive piece of identification. Unlike a password, it cannot simply be changed if misused. When combined with a name and date of birth, a passport number can support identity fraud. It can also be used to create fraudulent travel documents or open new accounts in someone else’s name.
Loyalty program data carries its own risks, even without a passport number attached. Scammers can use travel history, points balances, and booking details to write convincing phishing messages. For example, a fake email about a canceled reservation or missing points can trick a customer into giving up login credentials or payment details.
What is the company doing?
Accor says it responded quickly once it learned of the unauthorized access in July 2026. The company reports resetting the compromised vendor credentials to cut off further access. It also reset customer account passwords across the board as an added safeguard, rather than waiting to confirm which specific accounts were touched.
In addition, Accor notified customers of the ongoing investigation in mid-July 2026. After completing its internal review, the company sent more detailed notification letters to potentially affected individuals in September 2026. Accor also filed formal notice of the incident with the New Hampshire Attorney General’s Consumer Protection Bureau, as required under state breach notification law.
Because the filing is the primary public source of detail here, some aspects of Accor’s response remain unclear. The company has not publicly stated whether it is offering credit monitoring or identity protection services to affected customers. Anyone who received a letter should review it closely for any such offer.
What Should Affected Individuals Do?
Review Any Notice You Received
If Accor sent you a letter about this incident, keep it in a safe place. This document is your clearest proof that your information was potentially involved in the breach. It may also be needed later if you decide to pursue a legal claim.
Read the notice carefully for any details about which specific data types were affected in your case. Because the template used by Accor left this field blank for many recipients, your letter may contain more individualized information than what has been made public so far.
Freeze or Monitor Your Credit
Because a passport number was involved for at least one person, affected individuals should consider placing a fraud alert or credit freeze. This step can be taken for free with Equifax, Experian, and TransUnion. A credit freeze makes it much harder for someone to open new accounts using your identity.
In addition, check your credit reports regularly through annualcreditreport.com. This site allows free report access and can help you catch unauthorized activity early. Early detection generally means less damage and an easier recovery process.
Watch for Phishing Attempts
Because loyalty account data was exposed, be cautious of unexpected emails, texts, or calls about your Accor bookings or ALL points. Scammers often use real breach details to make phishing messages look legitimate. Never click links in unsolicited messages asking you to confirm account information.
Instead, log into your Accor account directly through the official app or website to check your booking or points status. If anything looks suspicious, report it directly to Accor and avoid responding to the original message. This simple habit can prevent a lot of downstream fraud.
Secure Your Accounts
Change your ALL loyalty account password immediately, even though Accor reports it already reset passwords as a precaution. If you reused that password anywhere else, change it there too. Reused passwords are one of the most common ways attackers expand access across multiple accounts.
Where available, turn on two-factor authentication for your travel and financial accounts. This adds a second layer of protection beyond just a password. As a result, even if a password is ever exposed again in the future, your account stays much harder to break into.
Consider Your Legal Options
If you received a notice linking you to the Accor data breach, you may be entitled to compensation. Companies that collect sensitive identifiers like passport numbers are expected to take reasonable steps to protect them, including proper oversight of outside vendors.
Because this incident involved a vendor credential compromise and a passport number, it may be worth speaking with a data breach attorney. A free case evaluation can help you understand your options and whether you qualify to join a claim.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
