Fun For Less Tours, Inc. Data Breach Exposes Government ID Numbers

Published: 21 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Fun For Less Tours, Inc. disclosed a data breach in September 2026 that exposed customers’ government ID numbers. The exact number of people affected has not been publicly disclosed. Affected individuals should place a fraud alert or credit freeze, monitor their credit reports, and watch for phishing attempts using their stolen information.

CompanyFun For Less Tours, Inc.
IndustryOther Commercial
Data Types ExposedGovernment ID Numbers
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedCalifornia Attorney General, Vermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Fun For Less Tours, Inc. Data Breach?

Fun For Less Tours, Inc. recently confirmed a data security incident involving sensitive customer information. The company, which arranges group travel packages, disclosed the breach through formal notifications filed with state regulators. As a result, affected individuals are now learning that their personal data may have been exposed.

The exact discovery date of the breach has not been publicly disclosed. However, the company filed its official notification in September 2026, which is when the public first learned of the incident. Because many companies take time to confirm the scope of an intrusion before notifying anyone, there is often a gap between initial detection and public disclosure.

Details about the specific attack method have not been made public. In addition, the company has not released information about how long the unauthorized access may have lasted. Once the issue was identified, Fun For Less Tours, Inc. appears to have moved to assess what data was involved and who needed to be notified.

As is typical in these situations, the company likely brought in cybersecurity specialists to investigate the scope of the intrusion. This kind of forensic review helps determine which systems were touched and which individuals had their information compromised. The notification filed with regulators indicates that this review has concluded enough to identify the categories of exposed data.

Who was affected?

The breach appears to primarily affect customers of Fun For Less Tours, Inc. who provided personal information, including government identification details, when booking travel services. Because the company operates in the group tour and travel sector, many affected individuals may have shared this information for identification purposes tied to travel bookings.

The exact number of people affected has not been publicly disclosed. Regulatory filings in states like Vermont and California do not always include a specific headcount. Therefore, individuals should watch for a direct notification letter from the company to confirm whether they are personally affected.

It also remains unclear whether the breach affected only U.S. residents or a broader customer base. Given that group travel companies often serve customers across multiple states, the geographic scope could be wide. Because travel bookings sometimes include minors as part of family or school group trips, there is also a possibility that some affected records belong to children.

What Information Was Potentially Exposed?

According to the breach notification, the primary category of information involved was government identification numbers. This type of data is highly sensitive because it can be used to verify identity in many financial and legal contexts. Below is a summary of what has been confirmed as exposed.

  • Government ID numbers (such as passport, driver’s license, or similar identification numbers)

Exposure of government ID numbers creates a meaningful risk of identity theft. For example, a stolen passport or driver’s license number can be used by criminals to open new accounts, apply for loans, or impersonate victims in other transactions. Unlike a compromised password, government ID numbers cannot simply be changed, which makes this type of exposure especially concerning.

In addition, criminals sometimes combine stolen ID numbers with other publicly available details to build a more complete profile of a victim. This can lead to more convincing phishing attempts or fraudulent account applications. As a result, affected individuals should treat this exposure seriously, even though financial account numbers were not identified in the disclosed categories.

What is the company doing?

In response to the breach, Fun For Less Tours, Inc. filed official notifications with state regulators. This step is a legal requirement in most states once a company confirms that residents’ personal information has been compromised. The company also appears to be notifying individually affected customers directly, consistent with standard breach response practice.

Specifically, the company filed notice with the Vermont Attorney General and the California Attorney General. These filings are part of the company’s broader legal obligation to inform regulators and consumers about the scope of the incident. Additional filings in other states may also exist.

Beyond regulatory notification, the company has likely taken steps to secure its systems against further unauthorized access. Many organizations facing similar incidents also work to strengthen network monitoring and access controls. However, specific technical remediation details have not been publicly disclosed at this time.

Affected individuals should carefully review any notification letter they receive from the company. This letter may include information about available protective services, such as credit monitoring or identity theft protection, if such services are being offered. Since these details vary by state filing, reading the full notice is important.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should begin monitoring their credit reports right away. Because government ID numbers can be used to open fraudulent accounts, catching suspicious activity early can limit financial damage. You can request a free credit report from each of the three major credit bureaus.

In addition, consider spacing out these free reports throughout the year for ongoing visibility. This way, you get a recurring check on your credit file rather than a single snapshot. If you notice unfamiliar accounts or inquiries, report them to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

Because government ID numbers were involved in this breach, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to take extra steps to verify your identity before approving new credit. This can help prevent someone from using your information to open accounts in your name.

For stronger protection, you may also want to consider a credit freeze. A credit freeze restricts access to your credit file entirely, which makes it much harder for identity thieves to open new accounts. While a freeze requires you to lift it temporarily when applying for credit yourself, many people find the added security worthwhile after a breach like this one.

Stay Alert for Phishing Attempts

Following any data breach, scammers often use exposed information to craft convincing phishing emails or text messages. Therefore, be cautious of any unexpected messages claiming to be from Fun For Less Tours, Inc. or related financial institutions. Never click links or provide personal information in response to unsolicited messages.

Instead, verify the legitimacy of any communication by contacting the company directly through a known phone number or website. This simple step can prevent you from falling victim to a secondary scam that builds on the original breach. Because attackers often pose as trusted companies, staying skeptical is one of your best defenses.

Safeguard Your Government-Issued Identification

If your passport, driver’s license, or other government ID number was involved, consider contacting the issuing agency to ask about your options. Some agencies offer guidance on monitoring for misuse or, in certain cases, reissuing identification numbers. This step is especially important because these numbers are difficult to change and often used for identity verification.

Furthermore, keep a close eye on any official correspondence related to your identification documents. For example, unexpected renewal notices or unfamiliar applications filed in your name could be signs of misuse. Reporting anything suspicious promptly can help limit the damage from this type of exposure.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Browse all recent data breaches →