Based on the information available at the main page of the tour operator Tez Tour's website, clients will have to say goodbye to their vacation dreams. When trying to open the site, the message "DATASUCKERS have hacked TEZ TOUR. All servers are compromised. Extracted and destroyed: 45,398,685 booking records, 21,515,914 tour orders, 52,176,283 hotel bookings, and 252,300,000 financial transactions. Total: 395,500,000 records – permanently lost." appears.
Clients have been informed that the company no longer has access to passports, card data, phone numbers, addresses and other such information; all data has been deleted. Attempting to open the site with a .com domain name also fails.
A reader contacted the editorial office – a client who purchased a tour departing in early October. The young man confirmed he faced problems with the website's functionality:
— I was about to pay the second part of my fee, and now the site won't open. The bot replied that technical work is underway. They said when the opportunity arises, they'll let us know how to pay.
If you are familiar with the situation from inside, please write to the journalist or our chatbot, it can be done anonymously.
As commercial director of the tour operator Vaskan Arzumansky reported, the incident affected the operation of the company's website, however no signs of tourist and partner data compromise have been detected:
— Immediately after detecting unauthorized activity, necessary measures were taken to localize the incident and protect information systems. To date, no signs of tourist and partner data compromise have been found. The company's ERP system was isolated in time and was not damaged.
The manager emphasized that current bookings are preserved, obligations to tourists and partners are being fulfilled in a normal manner. Specialists are conducting a comprehensive review of the infrastructure and identifying the causes of what happened. Service restoration will be carried out step by step after passing the necessary security checks.
Added
"One may demand compensation for moral harm"
We consulted a lawyer to find out how clients whose data leaked online are protected.
Ivan Raykevich
Member of the board of the public association for consumer rights protection
Here is what Ivan Raykevich noted:
— Article 19 of the Law “On Personal Data Protection” establishes liability for violation of this law and also secures the right of a personal data subject to claim compensation for moral damage when his/her rights in the field of personal data protection are violated. Moreover, moral damage is compensated independently of compensation for property damage and losses incurred by the personal data subject.
In simple terms, if a client's personal data leaked onto the Internet because the company failed to provide adequate protection, the client may demand compensation for moral damage.
Furthermore, failure to comply with measures ensuring the protection of personal data of individuals, pursuant to paragraph 4 of article 23.7 of the Republic of Belarus Code on Administrative Offenses, entails imposition of a fine ranging from 2 to 10 basic units, for individual entrepreneurs — from 10 to 25 basic units, and for legal entities — from 25 to 50 basic units.
Reminder: the basic unit this year equals 45 Belarusian rubles.