Carnival cruises hit by ransomware attack

(Image credit: Shutterstock.com / NAN728)

The world's largest cruise operator Carnival has revealed it was hit by a huge ransomware attack that may have seen customer data stolen by hackers.

The company, which welcomes around 13 million guests each year, declared that one of its brands was hit by an attack on August 15. 

The attack on the as-yet-unnamed brand likely included what Carnival called "unauthorized access to personal data of guests and employees", and may have affected some of its other brands as well.

Carnival cruises ransomware

"On August 15, 2020, Carnival Corporation and Carnival plc (together, the “Company,” “we,” “us,” or “our”) detected a ransomware attack that accessed and encrypted a portion of one brand’s information technology systems. The unauthorized access also included the download of certain of our data files," the company declared in its 8-K form filed with the Securities and Exchange Commission (SEC).

The filing did not mention any specific type of ransomware, or the steps taken by the company. However it did note that Carnival was expecting, "potential claims from guests, employees, shareholders, or regulatory agencies,"

Carnival employs over 150,000 workers across the globe, and owns a number of shipping brands including Cunard, AIDA, P&O Cruises, Princess Cruises, Carnival Cruise Line, Costa, Holland American Line, as well as the high-end luxury cruise line Seabourn.

The attack comes shortly after company revealed a data breach in March 2020 which saw customer personal information including payment information leaked online. The cruise industry has already been decimated by the worldwide coronavirus pandemic, and Carnival will hope that the fallout from this incident does not affect it too harshly.

“The travel industry is an extremely attractive target to cybercriminals, as they can collect and store personally identifiable information (PII) on billions of passengers every year, including passport numbers, credit card information, email addresses and much more," noted Anurag Kahol, CTO, Bitglass. 

"To thwart ransomware attacks and mitigate their impact, all organisations need advanced threat protection. Organisations should leverage security solutions that can identify and remediate both known and zero-day threats on any cloud application or service, and protect managed and unmanaged devices that access corporate resources and data. This includes solutions that can automatically block malware in the cloud that is both at rest or in transit."

"Additionally, organisations must ensure adequate employee security training to identify phishing attempts and illegitimate emails as phishing is the primary vector for ransomware attacks."

Via Reuters

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
Latest in News
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently making a major announcement about Avengers: Doomsday's cast on YouTube, and I think it's going to be a long-winded reveal
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch
Microsoft Copiot Studio deep reasoning and agent flows
Microsoft reveals OpenAI-powered Copilot AI agents to bosot your work research and data analysis