Data leak
Norwegian Cruise Line Holdings Data Breach β Employee Phishing Attack
Primary Source βIncident Details
Norwegian Cruise Line Holdings (NCLH), parent company of Norwegian Cruise Line, Regent Seven Seas Cruises, and Oceania Cruises, disclosed in July 2020 that it had suffered a data breach resulting from a phishing attack targeting company employees in March 2020. The incident occurred at the same time the cruise industry was forced to suspend all operations due to the COVID-19 pandemic. Unauthorized access to employee email accounts resulted in potential exposure of personal data including names, Social Security numbers, dates of birth, passport information, health-related information, and financial account information for employees, travel agency partners, and some customers. The scope varied by individual β not all exposed individuals had all data types compromised. NCLH notified affected individuals directly and offered credit monitoring services. The company was simultaneously dealing with the catastrophic operational shutdown of all three cruise brands due to COVID-19, making this one of several crises management had to navigate simultaneously in 2020.
Technical Details
- Initial Attack Vector
- Phishing β employees of Norwegian Cruise Line Holdings were targeted with phishing emails that resulted in unauthorized access to employee email accounts; attackers then accessed personal data of employees, travel agents, and some customers stored in those accounts
Timeline
- 2020-03-01 Breach occurred
- 2020-07-27 Publicly disclosed
- 2020-07-27 Customers notified