Hackers claim they wiped Tez Tour: 395 million records 'destroyed', tourists' passports and cards 'in our hands'; the operator says only the site is down

16.09.2026 8 min 28

On the evening of 15 September the front page of teztour.by, the Belarusian site of the tour operator Tez Tour, was replaced with a notice that the company "ceased to exist as of 15.09.2026". A group calling itself DataSuckers claimed it had spent about two weeks inside the operator's network, copied and then wiped 395.5 million records, overwritten the disks and deleted the backups, and it told customers that their passports, bank cards, phone numbers and addresses were "in our hands". Tez Tour confirmed an attack to Interfax the same night but described a much smaller event: the website was hit, the ERP system was isolated in time, no sign of a leak of tourist or partner data has been found, and existing bookings stand. As of midday Moscow time on 16 September both tez-tour.com and teztour.by were still unreachable.

In brief

  • The defacement listed 45.4 million booking records, 21.5 million tour orders, 52.2 million hotel reservations and 252.3 million financial transactions as destroyed. Those figures add up to about 371 million, not the 395.5 million the attackers claim, a discrepancy Habr noticed.
  • DataSuckers told Habr the entry point was a file-upload service that let them plant a file the web server executed as PHP inside a Docker container, from which the internal network, SVN repositories with database passwords and a Tomcat Manager were reachable. Nothing in that chain has been verified by anyone outside the group.
  • Tez Tour's commercial director Voskan Arzumanov says the incident affected the website only, that measures to contain it were taken immediately and that no compromise of customer data has been detected. Services are to be restored in stages after security checks.
  • For customers the two versions lead to the same advice. A tour operator holds passport scans, card details and travel dates; if any of it left the building, the first use will be phishing dressed as the operator, of the kind that followed the Latvian vehicle-registry breach in August.

What the attackers put on the site

CityDog, a Minsk outlet, captured the defaced page before it went offline. Under the announcement of the company's supposed closure came an itemised list of what had been "irreversibly destroyed", then a message to customers saying that their passport data, card data, phone numbers and addresses were now held by the attackers and that the company no longer had access to them because everything had been deleted. A second message, addressed to Tez Tour's administrators, mocked their competence, said every server had been "fully captured", the disks overwritten to prevent recovery and the backups deleted, and predicted it would take them days just to get back in. In comments to Habr, the group added technical detail: access was gained roughly two weeks earlier through the operator's file-upload service, which accepted a file the web server then ran as PHP code; that gave command execution inside a Docker container; the container itself was isolated but could see the company's internal network and corporate services; there the group found credentials for SVN source repositories whose configuration files held database passwords, and access to a Tomcat Manager console let it run code on production systems. It also said administrators were running old, vulnerable software and kept backups on the same server as the site. The international site tez-tour.com returned a 503 error the same evening.

395.5mrecords the attackers claim to have copied and destroyed; the itemised list adds up to about 371 million
252.3mfinancial transactions in the claimed haul, the largest single category
~2 weeksthe group says it spent inside the network before the defacement on 15 September
0signs of a customer-data leak found by the company, according to its statement to Interfax

What the company says, and what neither side has shown

Tez Tour's statement, given to Interfax Tourism by commercial director Voskan Arzumanov late on 15 September, does not dispute that there was an intrusion. It says that as soon as unauthorised activity was detected the company took steps to localise the incident and protect its systems, that no compromise of tourist or partner data has been identified so far, that the ERP system was isolated in time and was not affected, that all current bookings remain valid and obligations to tourists and partners are being met as normal, and that specialists are checking the whole infrastructure before services are brought back in stages. The gap between the two accounts is the usual one after a defacement. The attackers have published a list of numbers and a description of their route in, but no sample of the data, no file listings, no screenshots of database contents; the company has published a denial of any leak while its public systems are still down and its investigation, by its own account, is still establishing the cause. A group that has really overwritten production disks and backups would have no reason to keep the data secret, and a company that has really lost its booking database would struggle to say that bookings are intact. Neither of those tests has been run yet. The record count itself is inflated or miscounted: the four categories on the defaced page sum to roughly 371 million, and the 252 million "financial transactions" would include every payment line ever logged, not 252 million customers. Habr also recalls that in June another Russian operator, Fun&Sun, suffered what it called a "technical anomaly" that left paying customers without tickets, insurance and hotel vouchers for more than a month.

What is not confirmed: every technical detail of the intrusion comes from DataSuckers; there is no independent forensic account, no published data sample and no regulator statement in Russia or Belarus. Tez Tour has not said when the sites will return or whether it has notified Roskomnadzor or Belarus's data-protection authority. The claim that backups were destroyed and the claim that the ERP was isolated cannot both be fully true; which one is closer will become clear from how quickly bookings can be serviced this week.

What a customer should do this week

Treat the attackers' claim as possible until the company shows otherwise, because the cost of being wrong is asymmetric. A tour operator's file on a customer typically contains a passport scan, date of birth, home address, phone number, sometimes a visa application, plus the card used to pay and the exact dates when the household will be away from home. The first thing criminals do with that combination is write to the customer as the operator: a message saying the booking must be "reconfirmed", a refund form for the disrupted trip, a link to "restore access" to a personal account. Do not confirm or re-enter anything through a link in a message; call the agency you booked through, using the number on your contract, and ask for written confirmation of your tickets, hotel voucher and insurance directly from the airline, hotel and insurer where possible. Watch card statements for small test charges and consider asking the bank to reissue a card that was used on the operator's site. A passport number cannot be changed on request, but a leaked one is mainly a problem in combination with other data, so be suspicious of any call that already knows your travel dates. Large passport datasets have a way of resurfacing long after the breach, as the 220 million border records leaked from Vietnam showed this month, and Russia already leads the world in the number of leaked databases by one count.

What happened to Tez Tour?
On 15 September a group calling itself DataSuckers defaced teztour.by, claiming it had spent two weeks in the operator's network and destroyed 395.5 million records after copying customer data. Tez Tour confirmed an attack on its website but says no data leak has been found and bookings are intact. Both its sites were still down on 16 September.
Is customer data actually leaked?
Unknown. The attackers claim to hold passports, card data, phone numbers and addresses but have published no sample. The company says no compromise of tourist or partner data has been identified. Neither claim has been independently checked.
How did they get in, according to the attackers?
Through a file-upload service that executed an uploaded file as PHP inside a Docker container; from there they reached the internal network, found SVN repositories with database passwords in configuration files, and used a Tomcat Manager console to run code in production. Only DataSuckers has described this chain.
Are my bookings still valid?
The company says all current bookings remain valid and obligations are being met as normal. Confirm this with the agency you booked through, by phone, and ask for confirmations directly from the airline, hotel and insurer.
What should I watch for?
Messages posing as Tez Tour or your agency asking you to reconfirm data, claim a refund or restore account access through a link; calls that already know your travel dates; small unexplained card charges. Do not enter data through links; use the numbers on your contract.

russiabelarustez tourdata breachhackingtour operatordatasuckerspassport databank cardsphishingpersonal datatourismhackersdefacementcybersecurity

Read also