Skip to main content
LiMP VPN
All news

Hackers Hit Tez Tour: What the Attack Means for Travelers' Data

Hackers Hit Tez Tour: What the Attack Means for Travelers' Data

In short: On 15 September 2026, a group calling itself DataSuckers claimed to have breached tour operator Tez Tour and destroyed hundreds of millions of records — including passport data, bank card details and booking records. The company confirmed the cyberattack but disputed the claimed scale of the damage. The incident is a stark reminder of how much sensitive data travelers hand over to tour operators, and why that data needs protecting.

What happened on 15 September 2026

At around 6 p.m. Moscow time on 15 September 2026, visitors to the official Tez Tour website were greeted not by the homepage but by a message from a group called DataSuckers. The attackers claimed to have fully compromised the company's server infrastructure. The message cited specific figures: 45.3 million booking records, 21.5 million tour orders, 52.1 million hotel booking entries, and 252.3 million financial transactions — totalling approximately 395.5 million records allegedly destroyed or exfiltrated. Clients were told that their passports, bank card data, phone numbers and addresses were now "in our hands."

We track cyberattacks on consumer services in the LiMP VPN news section — follow it to stay ahead of emerging threats.

Tez Tour is one of the largest tour operators in the post-Soviet region, serving clients from Russia, Belarus, Kazakhstan and several other countries. The company handles millions of trips annually, which explains the claimed scale of the database.

The company's response: attack confirmed, scale disputed

Tez Tour responded quickly. IT specialists removed the defacement message, and CEO Voskan Arzumanov issued an official statement. He described the figures cited by the hackers as "fabricated." The company stated that its ERP system had been isolated in time and was not affected, that "no signs of compromise of tourist or partner data have been identified," and that all active bookings remain intact.

In short: the cyberattack itself is officially confirmed. Whether data was actually exfiltrated or destroyed remains an open question — no independent verification of the attackers' claims exists at the time of writing.

Why tour operators are attractive targets

The travel industry collects an unusually sensitive bundle of personal data. When you book a package tour, you typically hand over:

  • Passport copies — the primary identity document, required for visa applications and ticketing
  • Bank card data — card numbers, expiry dates and payment credentials
  • Phone numbers and email addresses — direct channels for phishing and fraud calls
  • Travel dates and itineraries — information that tells criminals when someone is away from home
  • Family member and children's data — in family bookings

This combination is valuable both for resale on darknet marketplaces and for targeted fraud: knowing a person's full name, passport number and phone number allows convincing impersonation of banks, tax authorities or the tour operator itself. That is why large travel companies are prime targets — a single successful attack can unlock data on millions of customers at once.

The real risks for travelers — even without a confirmed leak

Regardless of whether Tez Tour's database was actually compromised, the incident raises a question travelers rarely consider: you typically have no visibility into how a tour operator stores your data. Concrete risks to watch for:

  • Phishing "from the tour operator." After any breach story makes headlines, fraudsters send emails purporting to be from the company — asking you to "reset your password" or "claim compensation." If you are a Tez Tour client, treat any email from the company in the coming weeks with heightened scepticism.
  • Data interception during booking. When booking or paying on unsecured public Wi-Fi — at airports, hotels or cafés — your card data and authentication tokens can be intercepted in transit. LiMP VPN encrypts all traffic, preventing interception on open networks.
  • Misuse of passport data. A passport scan in a criminal's hands enables a range of fraud: loans taken out without the owner's knowledge, registration of shell companies, and targeted social engineering attacks.

How to protect your data when booking travel

You cannot avoid sharing personal data with tour operators — it is required by visa and ticketing systems. But you can significantly reduce the risk of that data being misused:

  • Always use a secure connection when paying. Never enter bank card details on public Wi-Fi without a VPN. LiMP VPN is available from $0.99/month and runs on the iOS and Android devices most travelers use to book trips.
  • Enable real-time card alerts. Every transaction should trigger an immediate push notification or SMS. This lets you catch unauthorised charges the moment they happen.
  • Use virtual cards for online payments. Many banks allow you to create a limited virtual card for a specific purchase. If those card details are compromised, your main account is unaffected.
  • Do not click links in emails claiming to be from your tour operator. If you receive an email asking you to "update your details" or "confirm your booking," open the website manually in your browser rather than clicking the link.
  • Check whether your data has appeared in known leaks. Breach-monitoring services let you check whether your email or phone number has surfaced in databases circulating on the darknet.

What this means for the industry

The attack on Tez Tour is not an isolated event. Cybersecurity analysts have noted a growing pattern of ransomware and destructive groups targeting the travel sector: customer databases are valuable, and security standards often lag behind the financial or public sectors. Large tour operators frequently run ERP systems built in the 2000s and have been slow to adopt modern data protection practices.

If a data breach involving Tez Tour clients is confirmed, the company would face serious regulatory consequences under Russia's Federal Law No. 152-FZ on Personal Data, which requires operators to protect personal data and notify Roskomnadzor of incidents. For now, the company maintains that client data was not compromised.

Sources

Hackers Hit Tez Tour: What the Attack Means for Travelers' Data