Shut down the same day it was discovered

Image:
Image credit: Carnival Corporation
A social engineering attack against an employee exposed customer names, addresses, and government-issued ID numbers at Carnival Corporation.
The company, which operates Carnival Cruise Line, Holland America Line, Princess Cruises and Seabourn, has already started notifying affected customers.
In a notice posted online, Carnival says its IT team saw “unauthorised activity involving an employee’s account” on 14th April. It discovered that a threat actor had used social engineering to compromise the account, and leveraged this to access “a limited portion of our company’s IT system.”
Carnival says it acted to block the activity quickly and began working with third party experts to bolster its security. However, a week after the incident was identified the company confirmed that the attacker had copied personal information from its systems.
The analysis is still ongoing, but the impacted data is already known to include customer names, email addresses, phone numbers, dates of birth and government-issued ID (such as passport and driving license) numbers
Carnival has not yet determined exactly how many customers have been impacted, but is in the process of notifying any identified via email. It is also offering customers in the USA two years of free credit monitoring with TransUnion.
The company had no further comment when we reached out for more information. For now, customers are advised to remain vigilant against threats of ID theft or fraud, and to contact law enforcement if you believe you have been the victim of such.