Rumored Carnival Data Breach Could Impact Cruiser Accounts | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A notorious organization known for hacking into systems in order to steal vast amounts of information may have gained access to Carnival Corporation’s massive data base.

Who Is Behind the Potential Breach

A laptop displays a screen with green code and a large Guy Fawkes mask, symbolizing hacking or anonymous activity—evoking events like the Carnival Data Breach. The laptop sits on a black surface with a white background.

While ShinyHunters may sound like a musical group you’d hire to entertain at your child’s birthday party, they are, in fact, far more sinister.

The organization has been behind some of the largest data breaches to take place over the past 25 years. Among their past victims have been companies as diverse as Microsoft, Pizza Hut even several universities.

Now, according to numerous reports, ShinyHunters is claiming to have accessed troves of Carnival Corporation information and issued a ransom threat.

What Carnival Is Doing

A brightly lit Carnival ship sails through a channel beside a sandy beach and a city with tall buildings. Several people are visible on the top deck as the city and coastline stretch into the distance.A brightly lit Carnival ship sails through a channel beside a sandy beach and a city with tall buildings. Several people are visible on the top deck as the city and coastline stretch into the distance.
(Photo courtesy of Carnival Cruise Line)

In a statement, a Carnival Corporation rep told Cruise Radio that “after detecting unauthorized online activity involving a singer user account, we acted quickly to shut it down and block any further unauthorized access and have notified law enforcement.”

The real questions revolve around what “single user account” was accessed and whether it may have opened something of a cyber wormhole which might serve as a gateway to far more information.

“Data privacy and protection are extremely important to Carnival Corporation,” the spokesperson continued, “and we’re working closely with trusted global security experts to be thoughtful and deliberate in our review of the data involved, recognizing that anonymous reports circulating online are not always accurate.”

Aboard the Carnival Radiance, the cruise ship deck at sunset offers a spectacular scene featuring a water slide and numerous lounge chairs. A large screen entertains those seated around tables. The serene waters make this moment magical, as a distant ship dots the horizon—truly an unforgettable journey.Aboard the Carnival Radiance, the cruise ship deck at sunset offers a spectacular scene featuring a water slide and numerous lounge chairs. A large screen entertains those seated around tables. The serene waters make this moment magical, as a distant ship dots the horizon—truly an unforgettable journey.

The “anonymous reports” mentioned are likely those which claim that information from several million accounts has already been released.

For example, the site HaveIBeenPwned wrote that ShinyHunters “published the [stolen] data publicly, which contained 8.7 million records with 7.5 million unique email addresses.”

The site went on to make the very specific claim that data released included information pertaining to Holland America Line — a division of Carnival Corporation — and their Mariner Society loyalty program.

It went on to say that the information included “names, dates of birth, genders and data relating to status within the loyalty program.” 

What Happens Next

Carnival Corporation & PLC logo with a red flag featuring a blue circle and white outline above the company name in black capital letters on a white background, highlighting awareness following the recent Carnival Data Breach.Carnival Corporation & PLC logo with a red flag featuring a blue circle and white outline above the company name in black capital letters on a white background, highlighting awareness following the recent Carnival Data Breach.

Meanwhile, the Carnival spokesperson concluded by saying, “If we determine personal information was affected, we will follow all disclosure requirements and communicate directly with any impacted individuals.” 

Meanwhile, HaveIBeenPwned.com recommends that if you believe your information may have been compromised, you should change your password immediately. They also suggest enabling two-factor authentification, which is standard advice when it comes to adding an added layer of protection to any and all accounts.

In 2020, Princess Cruises had a hacker gain access to company emails.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW