Hurtigruten
bd_d50a0c6264f2ed20 · schema v1 · pii pii-v1
Full breach record for Hurtigruten →Hurtigruten disclosed a ransomware incident where an unauthorized actor gained remote access to its network on December 14, 2020, encrypting parts of computer systems. The actor exfiltrated and later published guest data including names, dates of birth, passport numbers, and contact information for guests on MS Fram and MS Midnatsol voyages between 2016-2020. Credit card and SSN data were not affected. Hurtigruten contained the incident, engaged forensics, notified law enforcement (Norwegian and FBI), and offered 12 months of identity theft protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 14, 2020
Begins
Dec 14, 2020
Discovered
Mar 2, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Montana State AGbd_8189c3af2577e54f2021-03-01 · +1dCandidate
- Indiana State AGbd_b32cf2b00cd7a0002021-03-01 · +1dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.