DisclosureLens
HackingTransportation & LogisticsTransportationSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDMediumContained

Morning Star Tours

bd_2b352c628dc9653f · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jun 1, 2026

To disclose

Affected

17state residents only

Linked

7 filings

Confidence

66%

Morning Star Tours experienced a data security incident between April 22-23, 2026, involving the compromise of servers maintained by a third-party MSP. The incident potentially affected the names, dates of birth, and passport information of 17 New Hampshire residents. The company reported the incident to law enforcement, engaged cybersecurity counsel, and implemented remediation measures including organization-wide MFA and password resets. Notification letters were mailed on June 1, 2026.

Leak gap clock Leak >30d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

Apr 22, 2026

Begins

Jun 1, 2026

Filed

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 1d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Washington State AGMay 31 · first
Oregon State AGMay 31 · first
California State AGMay 31 · first
New Hampshire State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.