HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Morning Star Travel
bd_2b352c628dc9653f · schema v1 · pii pii-v1
Full breach record for Morning Star Travel →Morning Star Tours (MST) notified the New Hampshire Attorney General of a data security incident involving its third-party MSP. The incident occurred April 22-23, 2026, potentially affecting 17 NH residents. Impacted data included names, dates of birth, and passport information. MST reported the incident to law enforcement, engaged forensic counsel, and implemented security measures including MFA and password resets. Notifications were mailed June 1, 2026.
Leak gap clock⏱ Leak >30d6 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by pear about this victim predates this filing by 32 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0c1e4715642d603fLeak Sitepearfiled 2026-04-30(32d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_8f1c93ac9f2daf5cTexas State AGfiled 2026-06-01Verified by operator
- bd_2087657171354394Oregon State AGfiled 2026-05-31(1d gap)Verified by operator
- bd_7301f95c246ef549California State AGfiled 2026-05-31(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/morning-star-tours-20260601.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 2318e346a9f467ebe96a0eca41373bcd83d540f6cfda3bd49c1375966c2d4c0f
Reporting entity
- Name
- Pierson Ferdinand LLPnorm: pierson ferdinand
- Domain
- pierferd.com
Victim entity
- Name
- Morning Star Travelnorm: morning star travel
- Domain
- morningstartravel.org
Incident
- Discovered
- Apr 22, 2026
- Materiality determined
- —
- Notification sent
- Jun 1, 2026
- Affected individuals
- 17
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- reported the Incident to law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.