Perspectives

“We Have Your Passports”: Hackers Claim a TEZ TOUR Data Theft, but Their Figures Are 24 Million Records Short

Иллюстрация к теме: Ваши паспорта у нас: хакеры заявили о краже данных TEZ TOUR. Но в их цифрах не хватает 24 млн зап...

On 15 September, a message from hacker group DataSuckers appeared on TEZ TOUR websites. The attackers claimed they had spent two weeks inside the tour operator’s systems, copied customer data, destroyed servers and deleted backups.

The claimed scale is enormous: almost 395.5 million records, including bookings, tour orders and financial transactions.

TEZ TOUR confirmed a cyberattack but strongly disputed the hackers’ account. It said its main booking system was unaffected, active reservations remained intact and no signs of a tourist-data leak had been detected.

RAEM.KZ examined what was actually known about the attack at the original article’s publication, why the attackers’ arithmetic does not add up and what it meant for TEZ TOUR customers in Kazakhstan.

The TEZ TOUR Website Announced the Company’s End

The attack became public on the evening of 15 September. Instead of the usual tour-operator page, users saw a message from a group calling itself DataSuckers.

The hackers wrote that TEZ TOUR had supposedly “ceased to exist,” all its servers had been seized and its databases copied and destroyed.

According to the attackers, they gained access around two weeks before the public statement, studying the internal network and gradually expanding their privileges throughout that period.

The defaced page listed the following allegedly destroyed data:

  • 45,398,685 reservation records;
  • 21,515,914 tour orders;
  • 52,176,283 hotel bookings;
  • 252,300,000 financial transactions.

The hackers put the total at 395.5 million records.

A separate message addressed customers. DataSuckers claimed to have obtained tourists’ passport details, phone numbers, addresses and bank-card information.

The attackers also said they had overwritten disks and deleted backups, leaving the company without access to its databases and unable to recover quickly.

This sounds almost like the digital destruction of a business. So far, however, the claims are supported only by the hackers themselves.

They published no database samples, file lists, internal-system screenshots or other material allowing independent verification of the scale.

Even a Calculator Cannot Produce 395.5 Million

There is an odd detail in DataSuckers’ statement.

Adding the four categories listed on the defaced page produces 371,390,882 records.

That is 24,109,118 fewer than the claimed 395.5 million.

A calculation error does not prove the attack was invented. It does warrant greater caution about the attackers’ other figures.

A database record is also not an individual person.

One tourist can generate several records: an application, tour order, hotel booking, payment, refund, status change, insurance document or technical operation.

Even if the hackers’ figures are close to reality, they do not mean 395 million affected tourists.

The largest category is 252.3 million financial transactions. DataSuckers did not explain what it meant by a transaction.

These could include status changes, internal settlements with agencies and hotels, refunds, commissions and technical records, as well as customer payments.

The headline number is large, but what lies behind it is unknown.

The Attack May Have Begun With One Uploaded File

DataSuckers identified TEZ TOUR’s file-upload service as the entry point.

According to the hackers, the system allowed a file to be uploaded that the server treated as PHP code and executed, rather than as an ordinary document or image.

This allegedly let the attackers send commands to the server.

They described the subsequent chain as follows:

  1. They gained access to a Docker container, an isolated system component running a service.
  2. From the container, they connected to the company’s internal network.
  3. They found SVN repositories containing source code and settings.
  4. Database passwords were allegedly stored in configuration files.
  5. Through Tomcat Manager, they said they could then execute code in TEZ TOUR’s live system.

If accurate, this was more than one isolated flaw: unsafe uploads, weak isolation of internal services and accessible database passwords formed a chain.

The international web-application security project OWASP recommends allowing only necessary file types, validating contents and storing uploads separately from the live website. A server should not be able to execute a user-uploaded file as a program.

DataSuckers also claimed the company used outdated software and stored backups alongside primary systems.

If a backup was on the same server, it could be destroyed with the main database. That account has not been independently confirmed.

All technical details of the attack currently come from the attackers themselves.

TEZ TOUR Confirms the Attack but Denies a Leak

TEZ TOUR did not deny the incident itself.

Company representative Voskan Arzumanov said specialists restricted system access and isolated the ERP after detecting suspicious activity.

ERP is an internal platform that can handle applications, reservations and other core business processes.

According to TEZ TOUR:

  • its ERP system was unaffected;
  • active bookings were preserved;
  • tourist and partner data were not compromised;
  • customer obligations were being fulfilled;
  • travel-agency enquiries continued to be processed.

Arzumanov described the figures for destroyed bookings and transactions as fabricated.

The two accounts are almost directly opposed.

The hackers say they stole data, destroyed servers and deleted backups. The company says its main system was disconnected in time and preserved.

Neither side has presented independent technical-review findings.

The Company’s Wording Became More Cautious

When the original article was prepared, TEZ TOUR’s international website displayed a service page about restoring access.

The updated message described an incident affecting “individual parts of the IT environment.” Access to some systems and services was temporarily restricted, with gradual restoration following security checks.

TEZ TOUR stressed that it continued operating and serving customers.

The newer message did not separately state that no data leak had occurred. That does not mean a leak was detected; the company may simply have adopted more cautious language while its investigation continued.

The tourist online-booking portal was loading again. At the original publication, TEZ TOUR’s Kazakhstan website was also accessible, with destinations, customer accounts and application-status checks available.

A functioning website does not itself prove all internal systems have fully recovered. Public pages and booking databases can sit in different system components.

Could Customers in Kazakhstan Have Been Affected?

At the original publication, there was no confirmation that hackers had obtained data belonging to customers of the Kazakhstan operation.

TEZ TOUR operates as an international network. Its Kazakhstan website allows users to select and pay for tours, check application status and use personal accounts.

It is not publicly known where Kazakhstani tourists’ data is stored or how closely the local system connects to the infrastructure DataSuckers claims to have breached.

It is therefore impossible to say Kazakhstani customers’ data was stolen. Nor can the possibility be ruled out until the company explains which countries, servers and divisions were affected.

Tourists need to consider more than whether reservations survived. Tour operators may hold particularly sensitive information:

  • full names and dates of birth;
  • passport numbers and copies;
  • phone numbers and email addresses;
  • information about family members;
  • travel routes and dates;
  • hotels, tickets and insurance documents;
  • order and payment histories.

If criminals obtained that data, they could use it for highly convincing fraud.

Why Travel Data Creates Particular Risks

Imagine a call supposedly from a TEZ TOUR employee.

The caller knows your name, hotel, destination country and departure date. They then say that after the outage you must reconfirm passport details or urgently pay a small extra amount to prevent cancellation.

This sounds more convincing than a mass scam message because the caller already knows the journey’s details.

Another possible scenario is an email offering a refund because of the cyberattack. It sends a link to a fake website and requests card details to receive the money.

Even if the operator did not store full card details, order information can be sufficient for a targeted attack.

Travel dates create a further risk: knowing when someone leaves and returns reveals when their home may be empty.

Who Are DataSuckers?

DataSuckers is not among well-known hacker groups with extensively documented attack histories.

Before the TEZ TOUR incident, the name rarely appeared in public reporting or cybersecurity research.

It could be a new group, a temporary alias or a new name for existing attackers. Hacker teams regularly rename themselves, split and regroup.

That makes it impossible to assess DataSuckers’ reputation or how closely its claims match its capabilities.

So far, the group has demonstrated only that it could alter TEZ TOUR website content.

Defacing a public page is very different from accessing an entire international booking system.

Should Travellers Cancel Their Trips?

At the original publication, there were no grounds to cancel paid tours based on the available information.

TEZ TOUR said all active reservations were preserved and obligations to customers and partners were being fulfilled normally.

Travellers with upcoming trips should:

  • contact their travel agent using the number in their contract;
  • confirm booking and payment status;
  • download tickets, vouchers and insurance documents in advance;
  • keep copies of the contract and payment confirmations;
  • confirm directly with the hotel and airline if departure is imminent;
  • follow updates through official contacts only.

Do not pay for a tour again or share passport details merely because an email, message or caller requests it.

Genuine bank, tour-operator or security staff should not ask for SMS codes.

If a suspicious charge appears, block the card through the banking app. Change the TEZ TOUR account password, especially if it is reused elsewhere.

What Would Confirm an Actual Leak?

The confirmed facts at the original publication were a cyberattack, temporary suspension of some services and continuing recovery.

A leak of almost 400 million records was not confirmed.

That assessment would change with evidence such as:

  • a sample of the stolen database;
  • actual customer data publicly exposed;
  • an attempt to sell the information;
  • an official company breach notification;
  • a regulator’s statement;
  • independent technical-investigation findings.

TEZ TOUR still needs to answer key questions: which countries were affected, which systems attackers accessed, what data they held and whether independent specialists conducted a review.

The question is no longer whether the hackers could replace a website page. That is evident.

It is whether they really spent two weeks inside the systems and reached tourist data, or loudly claimed a victory they had not achieved.


Related Reading:

Понравился материал? Поделитесь с другими:

Picture of Раимбек Искендиров
Раимбек Искендиров
Picture of Раимбек Искендиров
Раимбек Искендиров

Похожие материалы

Reviews

Shield AI Valued at $12.7 Billion: Why Its Hivemind AI Pilot Is Transforming Military Aviation

American defense-technology company Shield AI has secured $2 billion in new funding and completed ...

Презентация Федерации цифрового и AI-спорта и детский турнир по искусственному интеллекту в Астане

AI

Digital and AI Sports Federation Unveiled in Astana Alongside Inaugural Youth AI Tournament

On October 2, during the Digital Bridge forum, the public presentation of the Republican ...

Венчурные фонды, акселераторы и инвестиции для стартапов в Казахстане

Startups

Kazakhstan Venture Capital & Accelerator Guide 2026: Where Startups Can Raise $50K to $1M+

Kazakhstan is rapidly transforming into the primary venture capital and technology hub of Central ...

Читайте нас в Telegram и Instagram

Подписывайтесь на наши каналы, чтобы первыми получать самые свежие новости казахстанской IT-индустрии, анонсы грантов, стажировок и эксклюзивные интервью.