← Accor

2026 Accor — employee-account LUKE scrape claim; 162,437 customer records (unverified)

2026 162.4K records affected Share on X

Data compromised

Actor-advertised partial customer database of 162,437 records: internal customer IDs, loyalty/membership info, names, language preferences, contact details, country, account-status metadata (password configured / needs update)—no plaintext passwords in BreachNews-reviewed sample; actor also claimed tens of millions more records were accessible but extraction interrupted—unverified

Technical writeup

Unverified hospitality customer-data claim — forum post dated July 15, 2026 (alleged intrusion July 14). BreachNews reported a newly created threat-actor account claimed access to Accor's internal LUKE platform via a compromised employee account, then scraped customer profiles by iterating user IDs until automated security terminated the session. The listing advertises 162,437 records; a sample reviewed by BreachNews showed structured customer profile fields including loyalty data and contact details without plaintext passwords. Broader claims of VPN/corporate-network access and tens of millions of accessible records were not independently evidenced. Accor had not issued a matching public statement at indexing time. BreachHistory catalogs the actor-cited 162,437 figure labeled unverified.

Root cause

Unverified cybercrime-forum claim that a compromised Accor employee account on internal platform 'LUKE' was used to scrape customer profiles until automated controls terminated the session—company had not confirmed at catalog time

References