Skip to content
Back to Blog
low severity May 31, 2026 · 4 min read

Morning Star Tours Data Breach Notice (Oregon Attorney General)

If you received a notice from Morning Star Tours, here’s what the filing says was exposed, and what to do about it.

Morning Star Tours notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on May 31, 2026. The filing puts the incident itself on April 22, 2026.

Morning Star Tours Data Breach Notice (Oregon Attorney General)

The personal information of 18,997 people was exposed in a breach at Morning Star Tours on April 22, 2026. The company filed its notice with the Oregon Department of Justice on May 31, 2026 — 39 days later.

If you received a letter from Morning Star Tours, your records were among those included. The filing states that the organisation must notify affected individuals directly, usually by post. Absence of a letter usually means you were not in the affected group, but anyone who has moved since April 22, 2026 should contact the company directly to confirm their status.

What the Exposed Personal Information Actually Enables

The record lists personal information as the category exposed. This typically includes name combined with details such as address and date of birth. These pieces of information do not expire. Unlike a credit card or password, they cannot be cancelled or rotated. Once they are out, they remain usable for identity theft and fraud for years.

Name plus date of birth is a common foundation for impersonation attempts. Criminals can use it to open accounts, file fraudulent tax returns, or apply for government benefits in someone else’s name. Address information adds precision, helping attackers tailor phishing messages or locate victims for more targeted scams.

No passwords were exposed. The filing does not list any credentials, and the record contains no indication that login details were compromised. This means your Morning Star Tours account itself is not at direct risk from this incident. You do not need to change any password for this service because of this breach.

The Gap Between Incident and Notification

The breach occurred on April 22 and the filing reached Oregon authorities on May 31. That 39-day window is the only timing information available. The record does not disclose when Morning Star Tours discovered the incident or how long the data was accessible before containment. State notification rules allow organisations time to investigate, so the interval alone does not prove delay or speed.

What matters most is that the exposure has already happened. The 18,997 affected individuals now face the long-term consequences of their personal details being outside the company’s control.

Why This Exposure Matters Even Without Government IDs

The filing does not list Social Security numbers, driver’s license numbers, or other permanent government identifiers. That is genuinely good news. It removes the highest-risk category that usually triggers urgent credit monitoring and tax fraud alerts.

However, the personal information that was exposed still carries real value on the underground market. Dates of birth and addresses are frequently paired with names to build synthetic identities or to support credential-stuffing attempts on other sites where you reuse the same email address. The absence of passwords here does not protect accounts you hold elsewhere if you have used the same login details across multiple services.

The scale — nearly 19,000 people — reflects the size of Morning Star Tours’ customer base rather than offering any judgment on the company’s security practices. The record itself establishes only the number affected and the categories involved.

How to Determine Whether You Are Affected

The clearest signal remains the letter. Morning Star Tours is required to notify each impacted customer directly. If you have not received one, your information was most likely not included. If you have changed addresses since April 22, 2026, reach out to the company to verify your status. Do not assume safety simply because time has passed without contact.

Practical Steps That Address This Specific Exposure

  • Place a fraud alert with the three major credit bureaus. Even without a Social Security number exposed, a fraud alert forces lenders to verify your identity before opening new accounts in your name. It is free and lasts for one year.
  • Review your credit reports for unfamiliar accounts. Check Equifax, Experian, and TransUnion once every four months through AnnualCreditReport.com. Look for anything opened after April 2026.
  • Monitor explanations of benefits and tax documents closely. Although medical data is not listed, watch for unexpected mail from insurers or the IRS that could indicate someone using your personal details.
  • Treat unsolicited calls or emails claiming to be from Morning Star Tours as suspicious. Use the contact information on their official website rather than replying to messages that arrive after this breach.
  • Consider identity theft protection services that offer dark-web monitoring for your name and date of birth. These cannot prevent every misuse but can alert you faster when your information appears for sale.

The exposure cannot be undone. What you can control is how quickly you detect and respond to any attempt to use your personal information. The letter from Morning Star Tours remains the definitive answer to whether you were included. For everyone else, this incident is a reminder that personal details retain value long after a single company loses them.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed May 31, 2026
Last reviewed July 22, 2026
Affected 18997
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email