DataBreachInformation.com
MonitoringCalifornia AG filing · September 21, 2026

Fun For Less Tours Confirms Data Breach of Customer Travel Details

Fun For Less Tours, Inc. filed a data breach report in California following an incident on October 27, 2025, impacting customer data. The breach, reported on September 21, 2026, exposed sensitive information including names, passport numbers, payment card details, and travel itineraries, which could lead to identity theft or financial fraud.

State
California
Breach date
October 27, 2025
Reported
September 21, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Passport Number
  • Payment Card Information
  • Billing Address
  • Email Address
  • Phone Number
  • Travel Itinerary and Booking History

Fun For Less Tours, Inc., a travel and tour planning company, filed a data breach report with California authorities. The filing indicates a security incident that occurred on October 27, 2025, with the report made public on September 21, 2026. The exact nature of the breach was not specified in the public record, and an investigation into the incident is currently ongoing.

The reported breach exposed various types of sensitive customer information. This includes individuals' Full Name, Date of Birth, Passport Number, Payment Card Information, Billing Address, Email Address, Phone Number, and Travel Itinerary and Booking History. This broad range of data could impact affected individuals in several ways.

The exposure of such detailed personal and financial data presents risks for those affected. Unauthorized access to passport numbers, full names, and dates of birth could be exploited for identity theft. Payment card and billing address information might be used for fraudulent transactions. Similarly, exposed email addresses, phone numbers, and travel itineraries could be leveraged for targeted phishing scams or other social engineering attempts.

If you received a notification letter from Fun For Less Tours, Inc., it is important to take protective measures. Consider placing a fraud alert or freezing your credit with major credit bureaus. Regularly monitor your credit reports, bank statements, and payment card accounts for any suspicious activity. Be vigilant against unexpected emails, calls, or texts, especially those requesting personal information, as these could be phishing attempts.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases