What Happened in the Conquest Adventures Data Breach?
Conquest Adventures, LLC has confirmed that hackers broke into its network and locked down company files using ransomware. The company shared these details in a notice filed with the Idaho Attorney General’s Office. As a result, hundreds of people now face potential exposure of sensitive identification documents.
The intrusion itself began in June 2026, when an outside party gained unauthorized entry into the company’s systems. Once inside, the attacker deployed ransomware to encrypt files across the network. Conquest Adventures later determined that the same intruder may have accessed personal records before the encryption took hold.
Because ransomware attacks often involve a period of hidden access before any files are locked, companies typically need time to figure out exactly what was taken. In this case, Conquest Adventures spent roughly a month investigating before confirming, in July 2026, that personal data had likely been compromised. The company then notified state regulators shortly afterward.
So far, Conquest Adventures reports no confirmed evidence that the stolen information has been misused. However, security experts generally caution that this doesn’t mean the risk has passed. Stolen identification data can sit unused for months before it surfaces on criminal marketplaces or gets used in fraud schemes.
Who was affected?
The breach affects people who did business with Conquest Adventures, likely including customers who booked trips, tours, or adventure services through the company. Because the company works directly with travelers, the exposed records reasonably belong to individuals who trusted the business with identification documents needed for travel-related bookings.
According to the notification, 868 individuals were affected in total, including 11 residents of Idaho. This means the breach’s reach extends beyond Idaho to other states, even though Idaho’s Attorney General’s Office was the only regulator specifically named in available reporting. The company hasn’t publicly disclosed a broader state-by-state breakdown.
Given that passport numbers were involved, it’s likely that at least some affected individuals used Conquest Adventures for international or cross-border travel arrangements. This raises the stakes for anyone whose identification records were tied to travel documentation rather than just a domestic account.
What Information Was Potentially Exposed?
Based on the notification filed with Idaho regulators, several categories of personal information were involved in this breach. These are documents that identity thieves specifically seek out because of how difficult they are to replace and how convincingly they can be used to impersonate someone.
- Full names
- Home addresses
- Driver’s license numbers
- Passport numbers
This combination is especially concerning because it pairs a person’s identity with government-issued credentials. Someone armed with a name, address, and driver’s license number can attempt to open new financial accounts, apply for loans, or even produce fraudulent identification in the victim’s name.
Passport numbers add another layer of risk beyond typical financial fraud. Criminals can misuse compromised passport information in travel fraud or immigration-related schemes, which means affected individuals should watch for unusual activity tied to travel bookings or visa applications, not just credit accounts.
What is the company doing?
After discovering the intrusion, Conquest Adventures worked to determine the scope of the compromised data before notifying anyone. This kind of forensic review typically involves examining server logs, isolating affected systems, and confirming exactly which records the intruder could have reached.
Once the investigation confirmed which individuals were affected, the company began notifying state regulators and impacted individuals in late July 2026. Conquest Adventures has also pointed affected individuals toward identity theft protection services, including enrollment through IDX, as part of its response to the incident.
What Should Affected Individuals Do?
Place a Fraud Alert or Credit Freeze
Because driver’s license numbers were exposed, affected individuals should contact Equifax, Experian, and TransUnion to place a fraud alert or full credit freeze. A freeze blocks new creditors from accessing your credit file, which makes it much harder for a criminal to open accounts in your name.
Setting up a freeze is free and can be done online or by phone with each bureau separately. While it adds an extra step when you apply for credit yourself, that small inconvenience is worth the added protection given what was exposed in this incident.
Monitor Your Credit Reports and Financial Accounts
In addition to freezing your credit, you should regularly check your credit reports for unfamiliar accounts or inquiries. You’re entitled to a free credit report from each bureau annually through AnnualCreditReport.com, and reviewing all three on a staggered schedule can help you catch problems early.
Also review your bank and credit card statements closely for unfamiliar charges. Because the company reports no confirmed misuse so far, staying vigilant now gives you the best chance of catching fraud before it grows into a larger problem.
Protect Your Passport From Misuse
If your passport number was part of this breach, consider contacting the U.S. Department of State to ask about your options. While a compromised passport number alone doesn’t necessarily require a new passport, the State Department can advise you on warning signs of misuse.
Watch for anything unusual involving your identity in a travel or immigration context, such as unexpected communications referencing travel you didn’t book. Because passport fraud can be harder to detect than typical credit fraud, staying alert to this specific risk matters here.
Watch for Phishing Attempts
Ransomware breaches are frequently followed by scammers who reference the incident to trick victims into giving up even more information. Be suspicious of unexpected calls, texts, or emails that mention Conquest Adventures or claim to offer help related to this breach.
Never click links or share personal details in response to unsolicited messages. Instead, verify any communication by contacting Conquest Adventures directly through a phone number or website you already know to be legitimate.
Enroll in Identity Theft Protection and Report Concerns
If Conquest Adventures offers identity theft protection through IDX, take advantage of that service. These programs often include monitoring for misuse of your personal information and can alert you quickly if something suspicious appears.
If you notice signs your information has already been misused, file a report with the Federal Trade Commission at IdentityTheft.gov. Because the exposed data included government identification numbers, consulting a data breach attorney for a free case evaluation can also help you understand your legal options.
More Information
Official data breach notification from Delaware Attorney General
Official data breach notification from California Attorney General
