← Princess Cruises

2019 Princess Cruises — employee-account intrusion (Apr–Jul); guest/crew PII; public notice Mar 2020

2019 Unknown records affected Share on X

Data compromised

PII and payment/health fields per Princess/Carnival-era disclosures—categories varied by person

Technical writeup

Princess Cruises (Carnival Corp. brand) disclosed suspicious activity first identified in late May 2019; forensics found unauthorized access to some employee email accounts from about April 11 through July 23, 2019. The company’s notice and trade press summarized exposure types as varying by individual but potentially including name, address, SSN, government ID (passport/driver’s license), payment card and bank data, and health information; timing of public notification drew regulatory scrutiny in a later multistate settlement wave covering Carnival portfolio practices. Public reporting also cited on the order of ~180,000 individuals in multistate attorney-general summaries for the broader 2019 Carnival portfolio incident—treat brand-level headcounts as not standardized in BreachHistory until primary filings allocate by line.

Root cause

Unauthorized access to employee email accounts used to store or handle guest, crew, and HR data

References