Fun For Less Tours Reports Data Breach Affecting Customer Information
Fun For Less Tours, Inc. filed a data breach report in Vermont concerning an unspecified security incident. This compromise potentially exposed sensitive customer details, including passport numbers and credit card information, collected during travel bookings. Individuals who received a notification should take proactive steps to protect their personal and financial security.
- State
- Vermont
- Reported
- September 21, 2026
What may have been exposed
- Full Name
- Date of Birth
- Mailing Address
- Passport Number
- Credit Card Information
- Payment Card Information
- Frequent Flyer and Loyalty Account Details
- Email Address
- Phone Number
Fun For Less Tours, Inc., a travel company specializing in vacation packages, reported a data security incident to the Vermont Attorney General on September 21, 2026. The nature of the breach was not specified in the public filing, but the company indicated a compromise of its digital infrastructure.
Due to the incident, certain sensitive customer data collected by Fun For Less Tours, Inc. may have been exposed. The categories of information involved include Full Name, Date of Birth, Mailing Address, Passport Number, Credit Card Information, Payment Card Information, Frequent Flyer and Loyalty Account Details, Email Address, and Phone Number. The exact number of individuals affected by this breach was not disclosed in the public record.
Given the nature of the travel industry, companies like Fun For Less Tours, Inc. routinely handle extensive personal information to facilitate bookings and international travel. The exposure of details such as passport numbers and payment information carries a risk of identity theft and financial fraud.
Individuals who receive a data breach notification letter from Fun For Less Tours, Inc. should review their financial statements and account activity for any unauthorized transactions. It is also advisable to consider placing a fraud alert or security freeze on credit reports to help prevent new accounts from being opened in their name.
Monitoring email for suspicious messages and being wary of unsolicited communication that requests personal details are also recommended steps. Updating passwords for online accounts, especially those connected to travel services or financial institutions, can further enhance personal security. These measures are general best practices to mitigate potential risks following a data compromise.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Vermont Attorney General filing
Related data breach cases
- Wellington at Seven Hills Homeowner's Association, Inc.
- Opportune LLP
- G.I. Medicine Associates, P.C.
- LeMaitre Vascular, Inc.
- Boston Capital Holdings LP
- Lincoln Investment Planning, LLC
- AVL Growth Partners, an Ampleo Company
- Ocracoke Health Center, Inc.
- Kurt J. Lesker Company
- Tessco, LLC
- Powerhouse Retail Services
- Nevada Estate Planning and Probate, LLC
- C2M LLC d/b/a Click2Mail
- HealthStream, Inc.