Skip to content
Back to Blog
low severity September 21, 2026 · 4 min read

Fun For Less Tours, Inc. Data Breach Notice (California Attorney General)

If you received a notice from Fun For Less Tours, Inc., here’s what the filing says was exposed, and what to do about it.

Fun For Less Tours, Inc. notified California residents of a data breach in a filing reported to the California Attorney General on September 21, 2026. The filing puts the incident itself on October 27, 2025.

Fun For Less Tours, Inc. Data Breach Notice (California Attorney General)

The personal information of an unknown number of California residents was exposed in a breach at Fun For Less Tours, Inc. that occurred on October 27, 2025. The company filed its notification with the California Attorney General on September 21, 2026 — an interval of 329 days, or roughly 10.8 months.

The gap between incident and notification is the most striking fact in the record

That nearly eleven-month period stands out because it is the only timing information available. The filing contains no discovery date, so it is impossible to know how long the company spent investigating after first learning of the incident. What matters to you is that the exposure itself happened in late October 2025, and official notice of the breach reached the state regulator more than ten months later.

What the exposed personal information actually means for you

The record states only that personal information was involved. It does not list Social Security numbers, driver’s license numbers, financial account details, passport numbers, medical information, or any other specific category. No passwords or credentials of any kind appear in the exposed data.

This is genuinely good news on the credential side. There is no basis for changing any password connected to Fun For Less Tours, and the company’s systems holding your account login are not known to have been compromised in a way that would require that step.

Personal information such as names, addresses, dates of birth, or contact details — if those were the elements included in your case — retains value to identity thieves for years. These details cannot be reissued like a credit card. Once they are out, they stay out. The risk is not immediate panic but long-term opportunistic fraud: someone using your name and date of birth to open accounts, file fraudulent tax returns, or impersonate you in lower-level verification processes.

How to determine whether this breach actually includes you

Fun For Less Tours is required to notify affected California residents directly, usually by mail to the last known address on file. If you have not received a letter, it is likely that your records were not part of the exposed group. However, if you have moved at any time since October 27, 2025, a letter may have gone to an old address. In that case, contact the company directly to confirm whether you were included.

Absence of a letter is meaningful but not absolute proof. The filing does not disclose how many people were affected, so scale remains unknown.

Why personal information alone still requires attention

Even without the high-value identifiers that trigger mandatory credit freezes in many cases, the combination of your name with a date of birth or address can be enough to bypass weaker verification systems. Fraudsters piece together fragments from multiple breaches. This incident adds one more reliable data point to any dossier already built from earlier exposures.

The absence of permanent government identifiers in the disclosed categories means the breach does not automatically require the full suite of credit-report freezes and fraud alerts that accompany SSN exposure. That does not make it harmless; it simply narrows the immediate protective steps you need to take.

What you can still control

You cannot change your name, date of birth, or past addresses, but you can reduce the damage an attacker could do with them. Monitor your financial accounts and tax filings more closely than usual for the next 12 to 24 months. Look for unfamiliar inquiries, new accounts opened in your name, or tax documents you did not expect.

Place a fraud alert with the three major credit bureaus if you have not done so recently. This forces creditors to verify your identity before opening new accounts and serves as an early warning system. It is simpler and less restrictive than a full credit freeze when no SSN exposure is confirmed.

Review explanations of benefits from any health plans and statements from banks or credit cards for unfamiliar activity. Even though medical or financial categories were not named in the filing, routine vigilance catches identity theft early.

Consider whether you need to update contact information with Fun For Less Tours so any future correspondence reaches you. If you have an account on their site, enable any available extra authentication features, though this breach does not appear to have compromised login credentials.

The record is narrow. It tells us what category of data left the company’s control and when the incident and notification occurred. It does not reveal how the breach happened, how long any unauthorized access lasted, or whether stronger controls could have prevented it. Those details remain outside the filing. What is certain is that your personal information, once exposed, cannot be taken back. The practical protection lies in the monitoring and verification habits you put in place now.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed September 21, 2026
Last reviewed September 21, 2026
Affected Unconfirmed
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email