Data breach
Morning Star Tours
- Records
- 80,475
- Breach date
- 30 April 2026Estimated
- Added
- 13 June 2026
What was exposed
9 types of data · 3 put you at serious risk
- Names80,475
- Dates of birth54,113
- Phone numbers49,934
- Passport numbers40,244
- Email addresses39,072
- Street addresses33,725
- Social security numbers4,930
- Driving licence numbers5
- Licence plates4
About this breach
Morning Star Tours, a Dallas-based travel company known for Biblical tours to the Holy Land, has been named as a victim by the ransomware group Pear. According to our investigation team, the breach involves roughly 80,475 records, and the estimated attack date is April 30, 2026. The company notified affected individuals that the incident involved infrastructure managed by a third-party technology provider, and that a forensic investigation determined the intrusion occurred between April 24 and April 30, 2026. Pear claimed responsibility on May 4, 2026, according to Ransomware.live, which tracks ransomware group claims.
Breach Timeline
April 24 to April 30, 2026: A third-party forensic investigation cited in the company's notification letter determined the incident occurred during this window.
May 4, 2026: The Pear ransomware group listed Morning Star Tours as a victim, per Ransomware.live.
June 1, 2026: Morning Star Tours issued a notification letter offering identity protection services, filed with the California Attorney General.
What Information Was Compromised?
Our analysis found the following data types in this breach: 80,475 names, 54,113 dates of birth, 49,934 phone numbers, 40,244 passport numbers, 39,072 email addresses, 33,725 street addresses, 4,930 Social Security numbers, 5 driver license numbers, and 4 vehicle plate numbers.
The company's notification letter, filed with the California Attorney General, said affected individuals' names may have been exposed alongside other personal details, including government-issued identification numbers such as passports. The letter stated the incident did not involve driver's license numbers or financial account or payment card information, though our analysis did identify a small number of driver license records in the exposed data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Passport numbers and Social Security numbers are among the most sensitive identifiers exposed in a breach. Criminals can use this combination for identity theft, fraudulent loan applications, tax refund fraud, and opening new accounts in a victim's name. Passport details can also enable targeted phishing attempts that appear convincing because they reference real travel documents.
Email addresses and phone numbers in the hands of scammers raise the risk of phishing calls and messages, including follow-up schemes that pose as breach notification or identity protection services. Street addresses and dates of birth can support more personalized social engineering.
The company stated in its notice that it has no evidence any personal information has been misused so far, but data exposed in a breach can circulate for years before it is exploited.
What Is Morning Star Tours Doing in Response?
According to the company's notification letter, Morning Star Tours launched an investigation upon discovering the incident, engaged forensic professionals, notified law enforcement, and took steps to contain the impact. The company is offering affected individuals complimentary identity theft protection services through IDX, including credit and CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and fully managed identity theft recovery services. Enrollment must be completed by September 1, 2026, or within 90 days of receiving a notification letter. Individuals can enroll at the IDX enrollment site or call 1-888-204-1471, Monday through Friday from 9 a.m. to 9 p.m. Eastern Time, excluding holidays. The company said it is also evaluating additional security measures to prevent a similar event.
What Should You Do If You Were Affected?
Enroll in the free IDX identity protection services before the September 1, 2026 deadline if you received a notification letter.
Place a free security freeze with Equifax, Experian, and TransUnion to block unauthorized new credit accounts in your name.
Review your credit reports for accounts or inquiries you do not recognize, and monitor bank and card statements.
Watch for phishing emails or calls that reference the breach, your travel plans, or your passport. Do not click links or share personal details with unverified callers.
Report suspected identity theft to the Federal Trade Commission at identitytheft.gov.
