Hackers claim they wiped Tez Tour: 395 million records 'destroyed', tourists' passports and cards 'in our hands'; the operator says only the site is down
On the evening of 15 September the front page of teztour.by, the Belarusian site of the tour operator Tez Tour, was replaced with a notice that the company "ceased to exist as of 15.09.2026". A group calling itself DataSuckers claimed it had spent about two weeks inside the operator's network, copied and then wiped 395.5 million records, overwritten the disks and deleted the backups, and it told customers that their passports, bank cards, phone numbers and addresses were "in our hands". Tez Tour confirmed an attack to Interfax the same night but described a much smaller event: the website was hit, the ERP system was isolated in time, no sign of a leak of tourist or partner data has been found, and existing bookings stand. As of midday Moscow time on 16 September both tez-tour.com and teztour.by were still unreachable.
In brief
- The defacement listed 45.4 million booking records, 21.5 million tour orders, 52.2 million hotel reservations and 252.3 million financial transactions as destroyed. Those figures add up to about 371 million, not the 395.5 million the attackers claim, a discrepancy Habr noticed.
- DataSuckers told Habr the entry point was a file-upload service that let them plant a file the web server executed as PHP inside a Docker container, from which the internal network, SVN repositories with database passwords and a Tomcat Manager were reachable. Nothing in that chain has been verified by anyone outside the group.
- Tez Tour's commercial director Voskan Arzumanov says the incident affected the website only, that measures to contain it were taken immediately and that no compromise of customer data has been detected. Services are to be restored in stages after security checks.
- For customers the two versions lead to the same advice. A tour operator holds passport scans, card details and travel dates; if any of it left the building, the first use will be phishing dressed as the operator, of the kind that followed the Latvian vehicle-registry breach in August.
What the attackers put on the site
CityDog, a Minsk outlet, captured the defaced page before it went offline. Under the announcement of the company's supposed closure came an itemised list of what had been "irreversibly destroyed", then a message to customers saying that their passport data, card data, phone numbers and addresses were now held by the attackers and that the company no longer had access to them because everything had been deleted. A second message, addressed to Tez Tour's administrators, mocked their competence, said every server had been "fully captured", the disks overwritten to prevent recovery and the backups deleted, and predicted it would take them days just to get back in. In comments to Habr, the group added technical detail: access was gained roughly two weeks earlier through the operator's file-upload service, which accepted a file the web server then ran as PHP code; that gave command execution inside a Docker container; the container itself was isolated but could see the company's internal network and corporate services; there the group found credentials for SVN source repositories whose configuration files held database passwords, and access to a Tomcat Manager console let it run code on production systems. It also said administrators were running old, vulnerable software and kept backups on the same server as the site. The international site tez-tour.com returned a 503 error the same evening.
What the company says, and what neither side has shown
Tez Tour's statement, given to Interfax Tourism by commercial director Voskan Arzumanov late on 15 September, does not dispute that there was an intrusion. It says that as soon as unauthorised activity was detected the company took steps to localise the incident and protect its systems, that no compromise of tourist or partner data has been identified so far, that the ERP system was isolated in time and was not affected, that all current bookings remain valid and obligations to tourists and partners are being met as normal, and that specialists are checking the whole infrastructure before services are brought back in stages. The gap between the two accounts is the usual one after a defacement. The attackers have published a list of numbers and a description of their route in, but no sample of the data, no file listings, no screenshots of database contents; the company has published a denial of any leak while its public systems are still down and its investigation, by its own account, is still establishing the cause. A group that has really overwritten production disks and backups would have no reason to keep the data secret, and a company that has really lost its booking database would struggle to say that bookings are intact. Neither of those tests has been run yet. The record count itself is inflated or miscounted: the four categories on the defaced page sum to roughly 371 million, and the 252 million "financial transactions" would include every payment line ever logged, not 252 million customers. Habr also recalls that in June another Russian operator, Fun&Sun, suffered what it called a "technical anomaly" that left paying customers without tickets, insurance and hotel vouchers for more than a month.
What a customer should do this week
Treat the attackers' claim as possible until the company shows otherwise, because the cost of being wrong is asymmetric. A tour operator's file on a customer typically contains a passport scan, date of birth, home address, phone number, sometimes a visa application, plus the card used to pay and the exact dates when the household will be away from home. The first thing criminals do with that combination is write to the customer as the operator: a message saying the booking must be "reconfirmed", a refund form for the disrupted trip, a link to "restore access" to a personal account. Do not confirm or re-enter anything through a link in a message; call the agency you booked through, using the number on your contract, and ask for written confirmation of your tickets, hotel voucher and insurance directly from the airline, hotel and insurer where possible. Watch card statements for small test charges and consider asking the bank to reissue a card that was used on the operator's site. A passport number cannot be changed on request, but a leaked one is mainly a problem in combination with other data, so be suspicious of any call that already knows your travel dates. Large passport datasets have a way of resurfacing long after the breach, as the 220 million border records leaked from Vietnam showed this month, and Russia already leads the world in the number of leaked databases by one count.