Attorney Advertising · Informational Only · Not Legal Advice · Editorial Policy

IHG Hotels Data Breach Class Action

InterContinental Hotels Group (IHG) faced multiple significant data breaches that triggered class action litigation and settlements. The primary incident occurred between August 1, 2016 and December 29, 2016, when hackers gained access to guest payment information at approximately 1,175 to 1,200 IHG-branded hotel properties across multiple hotel chains including InterContinental, Holiday Inn, Holiday Inn Express & Suites, Candlewood Suites, Crowne Plaza, Staybridge Suites, and Hotel Indigo. If you stayed at any of these properties during that period and used a credit or debit card for payment, you could be eligible for compensation from the resulting $1.55 million settlement that was finalized in 2020.

The breach exposed guests to potential credit card fraud and identity theft, meaning anyone who checked into an IHG hotel during those five months and paid by card should be aware of their rights to compensation. More recently, IHG suffered a second major incident in September 2022 when a ransomware attack struck the company’s central booking system and mobile applications, preventing guests from making new reservations and blocking access to the loyalty program for several days. This attack led to a separate class action lawsuit filed by hotel franchisees in Georgia federal court, demonstrating that data breaches impact not just guests but the hotel franchise network itself.

Table of Contents

What Payment Systems Were Compromised in the 2016 Breach?

The 2016 IHG data breach specifically targeted point-of-sale payment systems at hotel locations worldwide. Guest credit and debit card information was exposed to unauthorized access, meaning payment details that guests willingly provided at check-in or for purchases at the hotel became available to cybercriminals. The breach affected payment processing across multiple high-volume hotel chains, so the exposure was widespread—a guest paying for a room at a Holiday Inn in Chicago, a Crowne Plaza in London, or a Staybridge Suites in Seattle could all have been affected if they stayed during the breach window.

The compromise of payment data at this scale created obvious fraud risks. Some affected guests experienced unauthorized charges, fraudulent purchases made with their card information, and the need to dispute transactions with their banks and credit card companies. Unlike a single-merchant data breach that might affect one hotel location, the IHG breach spanned over 1,100 properties, meaning the potential victim pool numbered in the hundreds of thousands.

What Payment Systems Were Compromised in the 2016 Breach?

Settlement Terms and What Compensation Was Available

In 2020, IHG agreed to pay $1.55 million as a total settlement fund to resolve claims from guests whose payment information was compromised. This settlement cap was divided into two categories of eligible claimants: those who could document out-of-pocket expenses (such as credit monitoring fees or travel reimbursements) could receive up to $250 per claim, while guests who suffered actual fraudulent or unauthorized charges directly caused by the breach could receive up to $3,500. The settlement structure meant that compensation was not automatic—affected guests had to submit a claim with documentation proving their losses.

For someone who paid $35 for credit monitoring after the breach or had a fraudulent charge of $150 reversed by their bank, filing a claim could recover those actual expenses up to the $250 threshold. However, the $1.55 million cap created a significant limitation: as claims were paid out, the total settlement fund diminished, meaning if many thousands of guests filed legitimate claims, individual payouts might be reduced proportionally. Additionally, the settlement required claimants to meet specific deadlines and document their losses—claiming that you “probably” lost money due to the breach would not qualify without receipts, credit reports showing fraudulent accounts, or bank statements showing unauthorized transactions.

IHG Data Breach Timeline and ImpactBreach Begins (Aug 2016)1175 Relative Impact ScaleBreach Ends (Dec 2016)1175 Relative Impact ScaleSettlement Finalized (2020)155 Relative Impact ScaleRansomware Attack (Sept 2022)100 Relative Impact ScaleFranchisee Lawsuit Filed (2022)50 Relative Impact ScaleSource: PR Newswire, Law360, Doctor of Credit, Bloomberg Law

The 2022 Ransomware Attack and Its Operational Impact

In early September 2022, IHG’s systems came under attack by ransomware that disrupted the company’s central hotel booking system and mobile applications. For several days, guests attempting to book rooms online or through the IHG app could not complete reservations, and members of the IHG loyalty program lost access to their accounts and rewards. The attack was significant enough to make headlines and cause business disruption across the entire IHG hotel network, not just individual properties.

What made this 2022 incident distinct from the 2016 breach was that it targeted operational systems rather than (or in addition to) payment data. While the 2016 breach was about stolen guest payment information, the 2022 ransomware attack was about disruption—hackers either encrypted critical systems or threatened to do so unless the company paid a ransom. Franchisees who operate IHG-branded hotels filed a proposed class action in Georgia federal court, arguing that the attack caused them financial losses through lost bookings and business interruption during the days when reservations could not be processed.

The 2022 Ransomware Attack and Its Operational Impact

The Franchisee Class Action Lawsuit

While most data breach settlements focus on individual consumer victims, the 2022 ransomware attack spawned a different kind of class action: franchisees sued IHG for the losses they sustained. Hotel franchisees typically pay IHG a percentage of their revenue or a flat fee in exchange for the brand name, reservation system, and loyalty program access. When the central booking system went down, franchisees could not fulfill reservations, lost multi-day revenues, and incurred emergency costs trying to manage bookings manually or through alternative systems.

The franchisee class action in Georgia federal court represented a practical but less common form of data breach litigation. Rather than claiming identity theft or credit card fraud (as individual guest-victims would), franchisees were claiming business losses and unjust enrichment by IHG, which continued collecting franchise fees from properties that could not operate their core business function during the attack. This illustrates how data breaches and cyberattacks ripple beyond the direct victims (guests whose cards were compromised) to indirect victims (business partners who depend on the company’s systems).

What Personal Information Was at Risk from These Breaches?

The 2016 breach primarily compromised payment card data—cardholder names, card numbers, expiration dates, and potentially the three-digit CVV security codes. When this type of information is exposed, criminals can use it to make unauthorized purchases, create fraudulent charges, or sell the data to other criminals on dark web marketplaces. A guest who checked in and paid with a Visa card in September 2016 might have seen fraudulent charges appear weeks or months later, months after their hotel stay.

Payment card fraud from data breaches can also lead to identity theft if criminals use the stolen information to open new credit accounts in the victim’s name. For example, a compromised card could be used to open a mobile phone contract, a utility account, or a store credit card, all without the legitimate cardholder’s knowledge. This is why many settlement agreements like IHG’s included compensation for credit monitoring costs—affected guests had legitimate reasons to place fraud alerts on their credit files and monitor their credit reports for signs of identity theft. However, the warning here is that settlement compensation, even at the $3,500 maximum, often did not fully cover the time and stress required to resolve fraudulent accounts or clear one’s credit history.

What Personal Information Was at Risk from These Breaches?

How to File a Claim and Understanding Settlement Deadlines

If you believe you were affected by the 2016 IHG data breach, the first step is to verify your eligibility. You must have used a credit or debit card at an IHG-branded hotel (any of the chains mentioned above) between August 1, 2016 and December 29, 2016. Once you confirm this, you would need to gather documentation of your losses: credit monitoring statements, cancelled checks or credit card statements showing fraudulent charges you reported and had reversed, or other out-of-pocket expenses directly caused by the breach.

However, settlement claims have strict deadlines that have likely already passed—the settlement was finalized in 2020, and the claims window may have closed years ago depending on the specific settlement administrator’s schedule. For guests who missed the original deadline, filing a late claim is often not possible without extraordinary circumstances. For the more recent 2022 ransomware attack, if you are a franchisee, you would want to consult with an attorney about the class action in Georgia federal court, as different deadlines and evidence requirements apply to business loss claims than to individual consumer claims.

IHG’s Security Posture and Lessons for Travelers

The sequence of two major incidents—a payment breach in 2016 and a ransomware attack in 2022—raises questions about whether IHG adequately upgraded its security infrastructure in the six-year gap between the two events. Data breach incidents of this scale typically prompt companies to invest in network segmentation, encryption, intrusion detection, and incident response capabilities. However, the 2022 attack suggests that either IHG’s security improvements were insufficient or that the company faced an advanced threat that would have been difficult to prevent even with best-in-class defenses.

For travelers going forward, these incidents underscore the reality that no large hotel company is immune from data breaches or cyberattacks. Guests should monitor their credit reports for signs of fraud, use one-time card numbers or mobile payment systems when possible to reduce the exposure of full card details, and maintain fraud alerts on their credit files if they stay at multiple hotel chains. IHG has since become more transparent about security incidents and has improved its public communication about breach response, but the underlying lesson is that hospitality companies manage vast amounts of guest payment data and are attractive targets for cybercriminals.

You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase:

Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com. Was your data exposed? Track active breaches at DataBreachRadar.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy.