2020 P&O Cruises (Carnival Corp.) — ransomware event; guest/employee data access claims
Data compromised
Guest and workforce PII as characterized in Carnival-era incident reporting—categories and volumes vary by person and brand allocation
Technical writeup
Carnival Corporation & plc reported a ransomware incident in mid-August 2020 affecting portions of its IT network; public security reporting tied the event to unauthorized access and encryption of some systems at the world’s largest cruise operator. The company’s disclosures and specialist press described potential unauthorized access to or download of data relating to guests and employees across Carnival’s brand portfolio, of which P&O Cruises is a named line—alongside parallel coverage for sister brands. Forensic conclusions on exact row counts per brand were not uniformly broken out in first-wave reporting.
Root cause
Ransomware / criminal intrusion against corporate IT (per company and press narratives)