Skip to main content
Jump to a category page

Fun For Less Tours, Inc. discovered it was hit by ransomware the same day the attack happened — October 27, 2025. It still took the company 329 days, nearly eleven months, to tell its customers.

Fun For Less Tours, Inc., a Draper, Utah-based tour operator, has begun notifying customers of a ransomware attack that compromised files on its network. According to the company’s notice letter, Fun For Less Tours discovered on October 27, 2025 that it had been the victim of a ransomware attack, and an unauthorized third party accessed its computer network and acquired certain files. The company completed its review of the affected files on March 23, 2026, determining which customers’ information was involved — but notice to those customers didn’t go out until September 21, 2026, nearly six months after that determination and 329 days after the breach was discovered.

Source: Fun For Less Tours, Inc. notice letter; California Attorney General data breach report sb24-630062, filed 09/21/2026; Vermont Attorney General security breach notices table, dated 09/21/2026.

A Long Delay With No Clear Explanation

What stands out about this breach isn’t the ransomware attack itself — it’s the timeline afterward. Fun For Less Tours knew about the attack the day it happened. It knew which customers were affected by March 2026. And yet notice letters didn’t go out for another six months. Under California and other states’ data breach notification laws, companies are generally required to notify affected individuals without unreasonable delay once they know who was affected. A six-month gap between determining who was affected and actually telling them is the kind of delay that raises real questions.

What Information May Have Been Involved

Fun For Less Tours’ notice letter uses a merge-field placeholder for the specific data categories involved, and does not spell them out in the version reviewed for this post. A separate filing the company made with Vermont regulators lists the category “Government ID Numbers” for the one Vermont resident affected — but that label is broader than what California’s data breach law specifically covers, and it isn’t confirmed to mean a driver’s license or state ID number as opposed to, for example, a passport number. No confirmed, itemized list of exposed data is currently available.

Who’s Affected

Fun For Less Tours’ customers are its own past travelers — people who booked tours through the company. That makes this a defined, identifiable group rather than an anonymous population, even though the company has not released a total count. Vermont’s filing confirms at least one Vermont resident was notified; the full number of affected customers nationwide has not been made public.

What You Can Do Now

  • If you’ve ever booked a trip with Fun For Less Tours, watch for a notice letter and take advantage of the complimentary Experian IdentityWorks credit monitoring it offers
  • Review your credit reports and account statements for any unfamiliar activity
  • Watch for phishing attempts referencing Fun For Less Tours or a past trip you booked
  • Contact us for a free case review if you received a notice letter from Fun For Less Tours

Do You Have Legal Options?

Companies that collect customer information have a legal duty to notify affected individuals without unreasonable delay once they know who was affected. A 329-day gap between discovery and notice — and a nearly six-month gap after the company knew exactly who was affected — may itself support a legal claim, separate from whatever information was ultimately exposed.

If you received a data breach notice from Fun For Less Tours, contact Emery | Reddy today for a free case review.

FAQ

How long did it take Fun For Less Tours to notify customers?

329 days from the ransomware attack itself, and about six months from the date the company finished determining which customers were affected. The attack and its discovery both occurred October 27, 2025; the company determined who was affected by March 23, 2026; notice went out September 21, 2026.

What information was exposed?

The notice letter reviewed for this post does not itemize the specific data categories. A Vermont regulatory filing lists “Government ID Numbers” for the one Vermont resident notified, but this has not been confirmed to mean a driver’s license or state ID number specifically.

How many people are affected?

Fun For Less Tours has not released a national total. Vermont’s filing confirms at least one Vermont resident was notified.

Why does the length of the delay matter?

Data breach notification laws generally require companies to notify affected individuals without unreasonable delay once they know who was affected. Fun For Less Tours knew which customers were affected by March 2026 but didn’t send notice until six months later — a gap that isn’t explained anywhere in the public record.

Do I have a legal claim?

Companies that experience a data breach have a legal duty to notify affected customers without unreasonable delay. If you booked a trip with Fun For Less Tours and received a notice letter, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now