DisclosureLens
HackingTransportation & LogisticsTransportationSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)LowContained

Morning Star Tours

bd_7301f95c246ef549 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 30, 2026

Filed

May 31, 2026

To disclose

4 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

64%

Morning Star Tours experienced a data security incident involving infrastructure managed by a third-party technology provider. The incident occurred between April 24 and April 30, 2026, and was discovered on April 30, 2026. Personal information, including names and other data, may have been inadvertently exposed. The company engaged forensic investigators, notified law enforcement, and is offering identity theft protection services to affected individuals.

California clockDiscovered Apr 30, 2026Notified Jun 1, 202632d CA 30-day late4 weeks discovery → filing

Incident timeline

undetected · 6 days
discovery → filing · 4 weeks / 31 days

Apr 24, 2026

Begins

Apr 30, 2026

Discovered

May 31, 2026

Filed

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 1d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Washington State AGMay 31 · first
Oregon State AGMay 31 · first
California State AGMay 31 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.