LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Fun For Less Tours, Inc. Data Breach Notice (California Attorney General)

MEDIUM severityConfirmedHow we verify

Fun For Less Tours, Inc. Data Breach Notice (California Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 21, 2026
Fun For Less Tours, Inc. Data Breach Notice (California Attorney General)

Occurred October 27, 2025 · publicly disclosed September 21, 2026.

MEDIUM
Severity
1
Data types exposed
September 21, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Fun For Less Tours, Inc. disclosed a data breach that occurred on October 27, 2025, and was reported to the California Attorney General on September 21, 2026; an undisclosed number of individuals had personal information exposed. Anyone who received services from the company should review the notice and consider protective steps such as monitoring accounts and placing a fraud alert.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Fun For Less Tours, Inc. notified California residents of a data breach in a filing reported to the California Attorney General on September 21, 2026. The filing places the underlying incident on October 27, 2025. The number of people affected remains unknown, and the notice describes the exposed material only as personal information.

For customers and others who have shared details with a travel company, even a limited public record matters: it confirms that an incident occurred, that regulators were notified, and that personal information was involved, while leaving scale and exact contents unconfirmed in the available disclosure.

What happened

According to the California Attorney General filing, Fun For Less Tours, Inc. experienced a data breach incident dated October 27, 2025. The company later submitted a breach notice that was reported on September 21, 2026, informing California residents. Public detail in that record does not state how the incident was discovered, what systems were involved, whether data was exfiltrated or only accessed, or how many individuals were affected. The notice characterizes the exposed data as personal information without further itemization in the summary available here.

No additional technical findings, ransom claims, or independent forensic conclusions are included in the disclosed facts. Timing between the stated incident date and the later regulatory reporting date is part of the public record; reasons for that interval are not explained in the materials provided.

How a breach like this happens

Incidents that lead to notices of this kind commonly begin with unauthorized access to accounts, servers, or cloud services that store customer or operational records. Typical pathways—described here only as general background, not as findings about this case—include stolen or phished login credentials, exploitation of unpatched remote-access software, misconfigured file shares, or malware that captures data before detection. Once inside, an attacker may copy databases, export spreadsheets, or stage files for later removal.

Organizations often learn of a problem through internal monitoring, a service-provider alert, law-enforcement contact, or unusual account activity. Investigation then tries to determine what was touched, whether copies left the environment, and which individuals should be notified under state law. Many notices ultimately describe the result only in broad categories such as “personal information” when a full inventory is still incomplete or when statutes require notice based on the potential for exposure rather than a finished forensic list. No threat group is named in the Fun For Less Tours filing, and none should be assumed.

Who is Fun For Less Tours, Inc.?

Fun For Less Tours, Inc. operates in the travel and tour sector, arranging or selling leisure travel experiences. Companies in this line of business routinely collect information needed to book trips, process payments, communicate itineraries, and meet airline or lodging requirements. That can include names, contact details, dates of birth, passport or travel-document data, payment-related information, and emergency contacts, depending on the services offered.

A breach at a tour operator is consequential because the same records that make travel possible are also useful for identity fraud, targeted phishing that impersonates a travel brand, or social-engineering attempts against customers who expect emails about bookings and changes. Even when the public notice is brief, the sector’s reliance on personal and travel-related data explains why regulators require notification and why affected people treat the event seriously.

The information in question

The breach notification, as reflected in the California Attorney General report, states that personal information was exposed. It does not, in the facts available here, list specific data elements such as Social Security numbers, financial account numbers, driver’s license details, or passport numbers. Exact contents therefore remain unconfirmed beyond the broad category given in the notice.

Travel companies typically hold identity and contact data, reservation histories, and sometimes payment or document information required for tickets and lodging. That general pattern describes what such organizations often store; it is not a statement of what was confirmed stolen or viewed in this incident. Readers should treat only the disclosed label—“personal information”—as established by the filing and regard any finer inventory as undisclosed.

The real-world impact

For individuals, the practical risk is misuse of whatever personal details were involved: unwanted account-takeover attempts, phishing that references a real booking relationship, or broader identity fraud if sensitive identifiers were among the data. Because the notice does not specify fields or headcount, people cannot yet gauge severity from public sources alone and may need to rely on any direct letter or email they receive from the company.

For the organization, consequences include notification costs, potential regulatory follow-up, customer-support load, and reputational strain common after any confirmed breach. The filing itself does not assign fault, quantify financial loss, or describe remediation steps beyond the fact of notice to California residents. Impact on people outside California is not addressed in the summarized record.

Were you affected?

If you have been a customer or otherwise shared information with Fun For Less Tours, Inc., watch for an official notice from the company and treat unsolicited messages that urge urgent payment or credential entry with caution. Consider placing a fraud alert with major credit bureaus if you believe sensitive identity data may have been involved, review financial and travel-account statements for unfamiliar activity, and change passwords on related accounts—especially if you reused credentials. Keep any breach letter for reference when dealing with banks or credit agencies.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which may help you prioritize further monitoring even when a single company’s notice leaves headcount and exact data types incomplete.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyFun For Less Tours, Inc. security record
74/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Fun For Less Tours, Inc.’s full breach history →
RelatedMore incidents at Fun For Less Tours, Inc.

More recent breaches

Ridgeway Pharmacy Ltd Data Breach Notice (California Attorney General)September 21, 2026Ethan Conrad Properties Data Breach Notice (California Attorney General)September 21, 2026Friesen Group Data Breach Notice (California Attorney General)September 21, 2026United Underwriters Data Breach Notice (California Attorney General)September 21, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Fun For Less Tours, Inc. Data Breach Notice (California Attorney General) →

Source: California Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram