HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
Morning Star Travel
bd_7301f95c246ef549 · schema v1 · pii pii-v1
Full breach record for Morning Star Travel →Morning Star Tours experienced a data security incident involving infrastructure managed by a third-party technology provider. The incident occurred between April 24 and April 30, 2026, and was discovered on April 30, 2026. Personal information, including names and other data, may have been inadvertently exposed. The company engaged forensic investigators, notified law enforcement, and is offering identity theft protection services to affected individuals.
California clockDiscovered Apr 30, 2026 → Notified Jun 1, 202632d ✗ CA 30-day late4 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_0c1e4715642d603fLeak Sitepearfiled 2026-04-30(31d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_2087657171354394Oregon State AGfiled 2026-05-31Verified by operator
- bd_2b352c628dc9653fNew Hampshire State AGfiled 2026-06-01(1d gap)Verified by operator
- bd_8f1c93ac9f2daf5cTexas State AGfiled 2026-06-01(1d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624200
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2026
- Raw hash
- 1c609577193f8af389b2430345e983d31b34e838b4d3f4d886a350b4376577cc
Reporting entity
- Name
- Morning Star Travelnorm: morning star travel
- Domain
- morningstartravel.org
Victim entity
- Name
- Morning Star Travelnorm: morning star travel
- Domain
- morningstartravel.org
Incident
- Discovered
- Apr 30, 2026
- Materiality determined
- —
- Notification sent
- Jun 1, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via third-party technology provider
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 30-day late · 32dLeak >30dCA AG copy ≤15d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 30, 2026→ Notified: Jun 1, 202632d 30 calendar days CA 30-day late California Consumers notified: Jun 1, 2026→ AG copy submitted: May 31, 2026— 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.