Fun For Less Tours Listed by anubis Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Fun For Less Tours has been listed by the anubis ransomware group, with internal files reported as exfiltrated in the attack. The incident was disclosed on 1 December 2025; an undisclosed number of individuals may be affected, and anyone connected to the organisation should review their exposure and take protective steps.
Inside the incident
The only confirmed public detail is the December 1, 2025 listing by the anubis group. The organization states that files were removed during a ransomware attack, but independent verification of the claim or additional technical details has not been published. The scale of the operation, including how many customer records may be involved, remains unknown.
The group behind it: anubis
Anubis is a ransomware operation that has appeared in public listings over recent years. Groups of this type commonly use encryption to disrupt operations and separately remove data for later publication or sale if a ransom demand is not met. The listing of Fun For Less Tours constitutes the group’s claim of involvement; no separate confirmation from the company or investigators has been reported.
Fun For Less Tours and its sector
Fun For Less Tours operates in the leisure travel sector, arranging packaged tours that require collection of customer identification for bookings, flights, and border crossings. Organizations in this field routinely store names, addresses, passport numbers, dates of birth, and payment information to complete reservations and comply with regulatory requirements. A compromise in this sector can therefore affect records that are difficult for individuals to change.
What data was at risk
The listing describes internal files removed during the ransomware attack. The accompanying summary refers to customer passports and personal data. The exact categories of information contained in those files have not been independently verified or itemized by the company, so the full scope of exposed fields remains unconfirmed.
Why it matters
Passport numbers combined with other personal details can be used for identity fraud or to support further targeted scams. Travel companies hold data that is both sensitive and relatively static, increasing the duration of potential misuse. For the organization, the incident adds operational disruption from any encryption and raises longer-term questions about data-handling practices, though the company’s specific response has not been detailed publicly.
What to do if you're exposed
Anyone who has traveled with Fun For Less Tours should monitor bank and credit accounts for unusual activity and consider placing fraud alerts with major credit bureaus. Passport holders may also review government guidance on reporting suspected misuse of travel documents. Readers can run a free exposure scan of their email address to check whether their information has surfaced in known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Two Kings Casino Resort Listed by anubis Ransomware GroupWoodglen Medical Group Listed by anubis Ransomware GroupDeibel Laboratories Listed by anubis Ransomware GroupBeyer Law Group Listed by anubis Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Fun For Less Tours Listed by anubis Ransomware Group →
Publicly posted by anubis — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.