Carnival Corporation and plc disclosed a cybersecurity incident affecting US adult guests. Unauthorized third-party access to IT systems was detected on August 15, 2020. The breach impacted names, addresses, phone numbers, passport numbers, dates of birth, and in some cases, SSNs and health information. The company engaged a cybersecurity firm, notified law enforcement, and offered 12 months of credit monitoring.