Morning Star Tours
bd_2b352c628dc9653f · schema v1 · pii pii-v1
Morning Star Tours experienced a data security incident between April 22-23, 2026, involving the compromise of servers maintained by a third-party MSP. The incident potentially affected the names, dates of birth, and passport information of 17 New Hampshire residents. The company reported the incident to law enforcement, engaged cybersecurity counsel, and implemented remediation measures including organization-wide MFA and password resets. Notification letters were mailed on June 1, 2026.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 22, 2026
Begins
Jun 1, 2026
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitepearbd_0c1e4715642d603f2026-04-30 · +32dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Texas State AGbd_8f1c93ac9f2daf5c2026-06-01Verified
- Vermont State AGbd_ab0ebf3c34dffdc62026-06-01Verified
- Washington State AGbd_0e641fbac615e0f12026-05-31 · +1dCandidate
- Oregon State AGbd_20876571713543942026-05-31 · +1dVerified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- California State AGbd_7301f95c246ef5492026-05-31 · +1dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.