HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Carnival Corporation Ltd.
bd_1c3ab84ff5393d16 · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →Carnival Corporation notified Delaware AG of unauthorized third-party access to IT systems detected on August 15, 2020. Access occurred in early August 2020, impacting guest, employee, and crew data including names, addresses, passport numbers, DOB, and potentially SSN/health info. Company engaged cybersecurity firm, notified law enforcement, and offers 12 months credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/02/US-Adult-Guest-Sample.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 4, 2021
- Raw hash
- 738aa06e2eea553ef54f25f4c03b5acfc37e86dfc494f6044bbea88e1c4980c9
Reporting entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Victim entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Incident
- Discovered
- Aug 15, 2020
- Materiality determined
- —
- Notification sent
- Dec 11, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified appropriate regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 months(476 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.