DisclosureLens
HackingHospitalityHospitalityData ExfiltratedRansom DemandedPIIMediumContained

Hurtigruten Pluss AS

bd_28e44775fb20d264 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 14, 2020

Filed

Mar 3, 2021

To disclose

11 weeks

Affected · nationwide

4,01718 in this filing

Confidence

66%
Full breach record for Hurtigruten Pluss AS

Hurtigruten Pluss AS, a hospitality entity based in Norway, reported a cybersecurity incident to the Maine Attorney General. The breach occurred on December 14, 2020, involving an external system breach (hacking). The incident affected an estimated 4,017 individuals, including 18 Maine residents. Notification was sent on March 1, 2021. The filing notes a ransomware attacker copied information, though the specific ransomware family is not named in this summary.

Maine clockDiscovered Dec 14, 2020Filed with AG Mar 3, 202179d ME AG >30d11 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 11 weeks / 79 days

Dec 14, 2020

Begins

Dec 14, 2020

Discovered

Mar 3, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,017 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.