Cruise giant Carnival confirms data breach affecting nearly 6 million people
Carnival Corporation has confirmed a data breach impacting nearly 6 million individuals, stemming from a cyberattack attributed to the ShinyHunters hacking group. The attackers gained access through a compromised employee account and stole sensitive personal information, including passport and driver's license details. This incident highlights ongoing vulnerabilities within large organizations and the potential for significant data compromise.
The cyberattack against Carnival Corporation occurred in April and involved the ShinyHunters group gaining unauthorized access to a portion of the company's IT environment. This access was initially facilitated by a compromised employee account, allowing the attackers to copy personal data from Carnival's systems. The stolen information included a wide range of details for nearly 6 million individuals, encompassing names, addresses, contact information, and crucially, passport and driver's license numbers. Carnival’s delayed public confirmation of the breach, taking a month to disclose, reflects the complexity of investigating such incidents and ensuring accurate notification of affected parties.
