Carnival Corporation Ltd.
bd_f98a16396915c9b3 · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →Carnival Corporation and plc notified the Delaware Attorney General of a cybersecurity incident occurring between April 11 and July 23, 2019. The company identified suspicious activity on May 31, 2019, leading to an investigation that revealed unauthorized access by an unsanctioned third party. The breach affected approximately 6 million individuals nationwide, including roughly 10,000 Delaware residents. Affected data included names, addresses, phone numbers, email addresses, and, for some, Social Security numbers and credit card information. Carnival engaged forensic experts and offered complimentary credit monitoring.
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/10/20201014164332.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 13, 2020
- Raw hash
- 86dd83c6f3a694f9e9a1903f260ba06bf0595977219014199c7bcba0f037209d
Reporting entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Victim entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Incident
- Discovered
- May 31, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 6,000,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Delaware Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 months(501 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.