ROYAL CARIBBEAN CRUISES LTD
ent_019fa1e787e4c6580a7c6a80a5d80bed
Disclosures
9
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
502
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ROYAL CARIBBEAN CRUISES LTD
- Normalized
- royal caribbean cruises— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0000884887
- Domain
- None on record
Disclosure history (9)newest first
- Massachusetts State AGas victim2021-06-23
Royal Caribbean Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-06-23. 241 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-06-23
Royal Caribbean Cruises Ltd. reported that between February 6 and February 18, 2021, a third party gained unauthorized access to a limited number of employee email accounts. Affected data included names, contact info, dates of birth, government IDs (passports, driver's licenses), and tokenized payment card info. SSNs and full unencrypted payment cards were not involved. The company secured accounts, updated email access controls, and offered 24 months of credit monitoring to California residents.
- New Hampshire State AGas victim2021-06-23
Royal Caribbean Group notified NH AG of a phishing incident affecting 62 NH residents. Unauthorized access to employee email accounts occurred Feb 6-18, 2021; discovered Feb 12, 2021. Data included names, DOB, passport/license numbers, and partial payment info. Notices sent June 22, 2021. Incident contained; controls enhanced.
- Montana State AGas victim2021-06-22
Royal Caribbean Group notified Montana residents that between Feb 6-18, 2021, unauthorized access to employee email accounts exposed personal data including names, DOB, passport numbers, and partial payment card info. The incident was contained in mid-February 2021.
- Indiana State AGas victim2021-06-22
Royal Caribbean Cruises Ltd reported a data breach to the Indiana Attorney General. The breach occurred on 2021-02-06 and was reported on 2021-06-22. 80 Indiana residents were affected.
- Washington State AGas victim2021-06-22
Royal Caribbean Group notified Washington AG of a phishing attack affecting 502 Washington residents. Unauthorized access to employee email accounts occurred between Feb 6-18, 2021, discovered Feb 12, 2021. Data included names, DOB, government IDs, and partial payment card info. Notices sent June 22, 2021. Incident contained; credit monitoring offered.
- Montana State AGas victim2018-12-06
Royal Caribbean Cruises LTD notified Montana residents of a data breach occurring between April 4, 2018, and September 13, 2018. A phishing attack compromised employee email accounts, potentially exposing customer PII including SSNs, driver's licenses, medical records, and financial data. The company discovered the incident on October 22, 2018, notified the FBI, updated email controls, and offered 12 months of credit monitoring.
- New Hampshire State AGas victim2018-12-05
Royal Caribbean Cruises Ltd. notified New Hampshire AG of a phishing attack on employee email accounts occurring between April 4 and September 13, 2018. Discovered Oct 22, 2018. Affected 3 NH residents with PII including SSN, medical info, and financial data. FBI notified. Credit monitoring offered.
- Massachusetts State AGas victim2018-12-05
Royal Caribbean Cruises Ltd reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-05. 20 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (5)filed by group companies
◈ These filings were made by or about subsidiaries of ROYAL CARIBBEAN CRUISES LTD — not by ROYAL CARIBBEAN CRUISES LTD itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Indiana State AGvia Silversea Cruises Ltd.2022-04-27
Silversea Cruises Ltd reported a data breach to the Indiana Attorney General. The breach occurred on 2021-08-18 and was reported on 2022-04-27. 17 Indiana residents were affected. 2,000 individuals affected in total.
- New Hampshire State AGvia Silversea Cruises Ltd.2022-04-25
Silversea Cruises Ltd. notified the New Hampshire Attorney General of a data incident affecting 6 NH residents. Unauthorized access occurred between Aug 18-25, 2021, involving attempts to encrypt systems. Data accessed included PII, SSNs, financial accounts, and health info. Notices sent April 27, 2022, with 2 years credit monitoring.
- Massachusetts State AGvia Silversea Cruises Ltd.2022-04-25
Silversea Cruises Ltd. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-04-25. 58 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGvia Silversea Cruises Ltd.2022-04-22
Silversea Cruises Ltd. notified Montana residents that unauthorized remote access to company systems occurred between August 18-25, 2021. The incident potentially exposed names, DOB, SSNs, financial account numbers, and health information. The incident was contained in August 2021, and 24 months of credit monitoring via Equifax was offered.
- Maine State AGvia Silversea Cruises Ltd.2022-04-22
Silversea Cruises Ltd. reported a data breach impacting 2,000 individuals. The breach, which occurred between August 18 and August 25, 2021, was described as an external system breach or hacking incident. Information compromised included names and financial account numbers or credit/debit card numbers, along with their associated security codes or PINs. The company began notifying affected individuals on April 27, 2022, and offered 24 months of complimentary credit monitoring services through Equifax.