HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Carnival Corporation Ltd.
bd_1e5e7014d602908c · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →Carnival Corporation and plc submitted a data security breach notification to the California Office of the Attorney General on March 12, 2021. The incident involved unauthorized access to customer data, potentially exposing names, Social Security numbers, and financial account information. The company provided one year of free credit monitoring, cyber monitoring, and a $1,000,000 insurance reimbursement policy to affected individuals. The notification covers residents of multiple US states, including California, Iowa, and Kentucky.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_df459e2ce7c7cf54Oregon State AGfiled 2021-10-18Verified
- bd_b45cbe1068a6d457Maine State AGfiled 2021-10-16(2d gap)Verified
- bd_c8917be506d4829aMontana State AGfiled 2021-10-06(12d gap)Verified
- bd_e54ff2b7a469347aMontana State AGfiled 2021-05-21(150d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 367d gap
- bd_793b80455e0891bdOregon State AGfiled 2020-10-16(367d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-546577
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 18, 2021
- Raw hash
- 7d5d2f64e89fe4efb019267d0e8ca647a28ea9aa7f8f9edfda9a6066e31c670a
Reporting entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Victim entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- External
- Regulator citations
- Submitted Data Security Breach Notification to California Office of the Attorney General
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.