HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
SP Cruises Opco Limited ("Azamara Cruises")
bd_1c1328fc1da0c975 · schema v1 · pii pii-v1
Full breach record for SP Cruises Opco Limited ("Azamara Cruises") →SP Cruises Opco Limited (Azamara Cruises) notified the California Attorney General of an incident where an unauthorized actor accessed a single email account between August 16 and August 19, 2024. The company became aware of the access on August 19, 2024. The actor may have downloaded email contents, which included names and other personal information of affected individuals. The company revoked access, investigated the scope, and is offering credit monitoring services.
California clockDiscovered Aug 19, 2024 → Notified Feb 25, 2025190d ✗ CA 60-day late27 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3e041b8a0b2e2c4eMaine State AGfiled 2025-02-25Verified
- bd_a4a39ccb1685699fMaryland State AGfiled 2025-02-25Verified
- bd_e5969b11b4b9b6f7New Hampshire State AGfiled 2025-02-25Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-599143
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2025
- Raw hash
- c37dbf9bdf4b740fba7b10da2efca288d0af6ca3887e959c3af057bbc6c84e16
Reporting entity
- Name
- SP Cruises Opco Limited ("Azamara Cruises")norm: sp cruises opco limited azamara cruises
- Domain
- azamara.com
Victim entity
- Name
- SP Cruises Opco Limited ("Azamara Cruises")norm: sp cruises opco limited azamara cruises
- Domain
- azamara.com
Incident
- Discovered
- Aug 19, 2024
- Materiality determined
- —
- Notification sent
- Feb 25, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(190 days from discovery to filing)
- Compliance flags
- CA 60-day late · 190d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 19, 2024→ Notified: Feb 25, 2025190d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.