Morning Star Tours has notified customers that it experienced a data security incident involving infrastructure managed by a third-party technology provider that supports its operations. According to the company, a forensic investigation determined the incident occurred between April 24, 2026, and April 30, 2026, and Morning Star Tours became aware of it around April 30, 2026. This falls under what’s generally described as a third-party vendor breach, meaning the exposure happened through a service provider’s systems rather than Morning Star Tours’ own network. The company states it has no evidence at this time that any personal information has been misused as a result.
The letter is addressed to individual recipients rather than describing a total number of affected people, so the overall scope of this incident is not stated in the notification. If you received a letter, it means Morning Star Tours has identified you as someone whose information may have been involved.
What information was exposed?
- Your name
- An additional personal information field paired with your name — the specific type of data was not filled in on the copy of the letter filed with regulators, so we can’t confirm exactly what it was
- The letter specifically states the incident did not involve driver’s license numbers or financial account or payment card information
Out of an abundance of caution, Morning Star Tours has arranged free identity theft protection services through IDX, including credit and CyberScan monitoring (for 12 or 24 months, per your individual letter), a $1,000,000 insurance reimbursement policy, and fully managed ID theft recovery services. You can enroll at https://app.idx.us/account-creation/protect or by calling 1-888-204-1471, using the enrollment code included in your letter. The enrollment deadline is September 1, 2026, which is ninety days from the date of the letter.
What should you do now?
- Enroll in the free IDX identity protection services before the September 1, 2026 deadline, since this monitoring is being offered at no cost to you
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, as an extra layer of ongoing protection beyond the offered service
- Review your bank and credit card statements regularly for any charges or accounts you don’t recognize
- Request your free annual credit reports at www.annualcreditreport.com and look over them for unfamiliar accounts
- Consider placing a fraud alert with one of the three credit bureaus (Equifax, TransUnion, or Experian) — this makes it harder for someone to open new credit in your name
- If you’re especially concerned, you can place a free security freeze with each credit bureau, which blocks new credit from being opened without your consent
- Watch for phishing emails or calls that reference this incident, since scammers sometimes use breach news to trick people into giving up more information
- Report any suspicious activity to your financial institution, local law enforcement, or your state attorney general’s office
If you have questions, Morning Star Tours’ representatives can be reached at 1-888-204-1471, Monday through Friday from 9 am to 9 pm Eastern Time, for ninety days from the date of the letter.