Hurtigruten
ent_5dbfe29d58edc96773c9cdb0
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,017
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hurtigruten
- Normalized
- hurtigruten— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- hurtigruten.com
Disclosure history (3)newest first
- California State AGas victim2021-03-02
Hurtigruten disclosed a ransomware incident where an unauthorized actor gained remote access to its network on December 14, 2020, encrypting parts of computer systems. The actor exfiltrated and later published guest data including names, dates of birth, passport numbers, and contact information for guests on MS Fram and MS Midnatsol voyages between 2016-2020. Credit card and SSN data were not affected. Hurtigruten contained the incident, engaged forensics, notified law enforcement (Norwegian and FBI), and offered 12 months of identity theft protection.
- Montana State AGas victim2021-03-01
Hurtigruten notified Montana residents of a December 2020 ransomware incident where an unauthorized actor encrypted systems and exfiltrated guest data (names, DOBs, passport info). The company contained the breach, engaged forensic investigators, and notified law enforcement and regulators.
- Indiana State AGas victim2021-03-01
Hurtigruten reported a data breach to the Indiana Attorney General. The breach occurred on 2020-12-14 and was reported on 2021-03-01. 48 Indiana residents were affected. 4,017 individuals affected in total.