On the official website of the tour operator Tez Tour, on 15 September 2026, a message appeared from the group DataSuckers claiming to have seized servers and destroyed data. The company confirmed a cyberattack on the website but stated that it had found no signs of compromise of tourist or partner data.
WHAT HAPPENED TO THE WEBSITE
On the hacked website, it is claimed that DataSuckers gained access to the infrastructure approximately two weeks before the public statement and gradually expanded their privileges. The group also claimed to have destroyed more than 395 million records, including 45.4 million booking records, 21.5 million tour orders, 52 million hotel bookings and 252 million financial transactions.
In the message, the hackers also claimed to have accessed client data and deleted backups. However, this information comes directly from DataSuckers and has not been confirmed by an independent audit.
WHAT THE COMPANY STATED
As reported by Tez Tour, after detecting unauthorised activity, specialists localised the incident and took measures to protect the information systems. The ERP system (the company's resource management system) was isolated and, according to the tour operator's statement, it was not affected.
At the same time, Tez Tour's main website and its version for clients from Belarus became unavailable. The company reported that it is conducting a comprehensive infrastructure check and restoring services in stages after the necessary security checks.
HOW THE COMPANY ASSESSES THE STATE OF THE DATA
Commercial Director Voskan Arzumanov stated that no signs of a leak of tourist or partner data had been identified. According to him, existing bookings are being retained, and the company continues to fulfil its obligations to tourists and partners as normal.
WHAT IS KNOWN ABOUT THE METHOD OF ATTACK
According to DataSuckers, the entry point was a file upload service. The hackers claim that they uploaded a file which the web server processed as PHP code (code executed on the server), which allowed them to execute commands inside a Docker container (an isolated environment for running applications).
Then, according to their claim, through access to the internal network, the hackers found credentials for SVN repositories (storage for source code and project files) with configurations containing database passwords. The group also claimed to have accessed Tomcat Manager (an application server management tool), which, according to them, allowed code to be executed in the production environment.
Фонд-бюро расследования коррупции