HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Royal Caribbean Group
bd_10a03950041cff76 · schema v1 · pii pii-v1
Full breach record for Royal Caribbean Group →Royal Caribbean Cruises Ltd. reported a data breach occurring between Feb 6-18, 2021, where unauthorized third-party access to employee email accounts exposed customer PII including names, DOBs, passports, driver's licenses, and partial payment card data. The incident was contained in mid-February 2021, and affected individuals were offered credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_02a73a19a3fdf0d9Montana State AGfiled 2021-06-22(1d gap)Candidate
- bd_93b51c73b5c1e10aWashington State AGfiled 2021-06-22(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542141
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2021
- Raw hash
- acd83458e4cda708291c847fc809fe78c21201856095321140c214ea9fb5d8f3
Reporting entity
- Name
- Royal Caribbean Groupnorm: royal caribbean
Victim entity
- Name
- Royal Caribbean Groupnorm: royal caribbean
Incident
- Discovered
- Feb 18, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(125 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.