In short: On September 15, 2026, hacker group DataSuckers claimed to have breached travel operator Tez Tour, stealing over 395 million records — including passports, bank card numbers, phone numbers and financial transaction histories of millions of tourists. The company confirmed the attack but denied any evidence of customer data leakage. If you have ever booked through Tez Tour, take action now.
What happened at Tez Tour
On September 15, 2026, visitors to tez-tour.com found a defacement message on the homepage: the company's servers had been seized and storage drives compromised. The perpetrators, DataSuckers, replaced the site with a detailed breach announcement describing how the attack was carried out and claiming enormous volumes of stolen data.
According to the hackers, they had initially gained access to Tez Tour's infrastructure approximately two weeks before going public — around September 1, 2026. During that time they methodically escalated privileges and exfiltrated data before revealing themselves. This "silent presence" tactic — maintaining access for weeks before a public disclosure — has become characteristic of several threat groups in 2025–2026.
Tez Tour is one of Russia's largest travel operators with offices in Russia, Belarus, Kazakhstan and several other countries, processing millions of bookings annually. The company's website remained offline for several days following the incident.
What data may have been exposed
DataSuckers published a detailed breakdown of the alleged stolen records:
- 45.4 million booking records
- 21.5 million tour orders
- 52.2 million hotel reservations
- 252.3 million financial transactions
The total claim exceeds 395 million records. The attackers stated that the databases contained tourist passport data, bank card numbers, phone numbers and physical addresses — among the most sensitive personal data categories, routinely exploited for identity theft, card fraud and targeted phishing. For guidance on checking whether your data appears in known breach databases, visit our security blog.
An important caveat: the hackers claim to have destroyed the exfiltrated data after obtaining it. There is no independent verification of this claim, nor of the stated volume of 395 million records. In practice, threat groups frequently sell stolen data on closed forums well before making public announcements.
How the breach was carried out
DataSuckers described their attack chain in considerable technical detail — one that illustrates common corporate security failures:
- Initial access: a file upload service with insufficient content validation. Attackers uploaded a file containing PHP code that the server executed as a script.
- Lateral movement: from the Docker container they accessed the company's internal corporate network.
- Privilege escalation: SVN source code repositories contained configuration files with database passwords stored in plaintext.
- Production code execution: access to Tomcat Manager allowed the attackers to execute arbitrary code in the live production environment.
The group cited outdated software and storing backup copies alongside primary infrastructure as the primary reasons the attack succeeded — classic and long-documented corporate security failures that continue to appear at large organizations.
What the company says — and what travelers should do now
Tez Tour officially confirmed the cyberattack. The company stated that its ERP system was isolated immediately upon detection, all active bookings were preserved, and obligations to clients and partners are being fulfilled normally. "No evidence of personal data leakage has been detected," the company's press service said.
Regardless of the official position, if you have ever used Tez Tour, security professionals recommend taking these steps without waiting for official confirmation:
- Bank cards: request replacement cards used for any Tez Tour bookings. This takes a few days but eliminates the risk of unauthorized charges.
- Passwords: if you reused your Tez Tour account password on other services, change it everywhere immediately.
- Phishing awareness: in the coming weeks, be especially alert to emails from "Tez Tour," "customer support" or "your bank" requesting data confirmation — a standard secondary attack pattern following major public breaches.
How to protect your personal data effectively
The Tez Tour incident is a vivid reminder that our personal data sits with dozens of companies whose security posture we cannot directly control. Here are practical steps that meaningfully reduce your exposure:
Unique passwords and a password manager. The most common reason a data breach causes downstream harm is password reuse across services. A password manager (Bitwarden, KeePass) lets you store a unique, complex password for every site without having to remember any of them.
Two-factor authentication (2FA). Even if a password ends up in the wrong hands, a second factor stops most automated attacks. An authenticator app (Google Authenticator, Microsoft Authenticator) is more reliable than SMS codes, which can be intercepted.
Breach monitoring. Haveibeenpwned.com lets you check whether your email address has appeared in known breach databases. The check is free and takes seconds.
Network-level data protection. When booking travel from a laptop in a café, airport or hotel, your traffic is visible to the network owner. The LiMP VPN app encrypts your connection — your ISP and the hotspot owner cannot see the content of your requests, including card data and personal details entered into booking forms. The no-logs policy means the service keeps no record of your activity. Learn more about how it works in the features section.
No single measure provides absolute protection — but combining them substantially reduces the damage from breaches that happen on the side of companies we have trusted with our data.
