Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumActive
SP Cruises Opco Limited ("Azamara Cruises")
bd_a4a39ccb1685699f · schema v1 · pii pii-v1
Full breach record for SP Cruises Opco Limited ("Azamara Cruises") →Azamara Cruises notified the Maryland AG of unauthorized access to a single email account between Aug 16-19, 2024. 97 Maryland residents affected. Data included names, gov IDs, and medical info. Incident likely caused by phishing. Response included account revocation, forensic review, credit monitoring, and regulatory notifications.
Maryland clock✗ MD AG >90d27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1c1328fc1da0c975California State AGfiled 2025-02-25Candidate
- bd_3e041b8a0b2e2c4eMaine State AGfiled 2025-02-25Verified
- bd_e5969b11b4b9b6f7New Hampshire State AGfiled 2025-02-25Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376417.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2025
- Raw hash
- 2fce3bc921b84ff5bcbccf5d3f8869fe7bda48d82688b287f80074a122b7747c
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- SP Cruises Opco Limited ("Azamara Cruises")norm: sp cruises opco limited azamara cruises
- Domain
- azamara.com
Incident
- Discovered
- Aug 19, 2024
- Materiality determined
- —
- Notification sent
- Feb 25, 2025
- Affected individuals
- 97
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney GeneralProviding written notice to relevant state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 weeks(190 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.