MalwareRansomwareData EncryptedData ExfiltratedData PublishedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Hurtigruten
bd_d50a0c6264f2ed20 · schema v1 · pii pii-v1
Full breach record for Hurtigruten →Hurtigruten, a cruise line operator, disclosed a ransomware incident on December 14, 2020, affecting guests of MS Fram (2018-2020) and MS Midnatsol (2016-2020). The attacker encrypted systems and exfiltrated names, DOBs, and passport data. Hurtigruten contained the breach, engaged forensic investigators, and offered 12 months of LifeLock identity theft protection.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538836
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2021
- Raw hash
- cb38e978104b203642aa0df28f166349818cbd9a63be739c8ba039b32ad541fb
Reporting entity
- Name
- Hurtigrutennorm: hurtigruten
- Domain
- hurtigruten.com
Victim entity
- Name
- Hurtigrutennorm: hurtigruten
- Domain
- hurtigruten.com
Incident
- Discovered
- Dec 14, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this matter to Norwegian law enforcement and the Norwegian Data Protection AuthorityNotified the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.