Hilton Grand Vacations Reports Data Incident to Massachusetts AG
Hilton Grand Vacations filed a data breach report with the Massachusetts Attorney General on February 20, 2026, indicating an unauthorized intrusion into its digital environment. While specific details about the exposed personal information and affected individuals are not yet public, the company is actively investigating the incident. This filing serves as official notice for individuals who may have received a notification letter from Hilton Grand Vacations regarding their data security.
- State
- Massachusetts
- Reported
- February 20, 2026
Hilton Grand Vacations, a hospitality and vacation ownership company, formally reported a data security incident to the Massachusetts Attorney General on February 20, 2026. This filing indicates that an unauthorized intrusion occurred within its digital environment, potentially affecting personal information.
The official public record available at the time of this filing does not specify the exact categories of personal information involved in this incident. Similarly, the number of individuals whose data may have been exposed has not been detailed. The company has stated that the incident is currently under investigation.
Individuals who receive a direct notification letter from Hilton Grand Vacations should carefully review that document for any specific details provided about the nature of the breach and the information involved. It is important to compare any such notice against public records to ensure accuracy.
Given the general nature of the reported incident, all individuals should exercise caution. It is advisable to closely monitor financial account statements and free credit reports for any unusual or unauthorized activity. Placing a fraud alert or security freeze on your credit files can add a layer of protection against identity theft.
Furthermore, regularly update passwords for all online accounts, especially if credentials were reused across multiple services. Be wary of unsolicited communications, such as emails or phone calls, that ask for sensitive personal details. Always verify the legitimacy of requests directly with the organization through official channels.