Carnival Corporation Ltd.
bd_c8917be506d4829a · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →14 incidents on fileCarnival Corporation notified Montana residents of a data breach detected on March 19, 2021, involving unauthorized access to email accounts. The incident impacted guest, employee, and crew personal information including names, addresses, passport numbers, DOBs, health info, and SSNs. The company engaged a cybersecurity firm, notified regulators, and offered one year of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 15, 2021
Begins
Mar 19, 2021
Discovered
Oct 6, 2021
Filed
vs. sector median
+21 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_b45cbe1068a6d4572021-10-16 · +10dVerified
- California State AGbd_1e5e7014d602908c2021-10-18 · +12dVerified by operator
- Oregon State AGbd_df459e2ce7c7cf542021-10-18 · +12dVerified
- Montana State AGbd_e54ff2b7a469347a2021-05-21 · +138dVerified
Show 1 more filing ↓Show fewer ↑up to 355d gap
- Oregon State AGbd_793b80455e0891bd2020-10-16 · +355dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Oct 16 (OR), last Oct 18 (OR) — a 367-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.