2021 Royal Caribbean Group — unauthorized access to limited employee email accounts (Feb 6–18)
Data compromised
Mixed PII categories enumerated in AG-filed notification samples (travel-style identifiers and demographic/contact fields)
Technical writeup
Between February 6 and February 18, 2021, a third party gained unauthorized access to a limited set of employee email accounts tied to Royal Caribbean Group operations, per regulatory breach samples filed with the California Department of Justice and summarized by sector incident trackers. The notices describe potential exposure of passport numbers, government IDs, DOBs, and contact fields for affected passengers or counterparties whose correspondence sat in those mailboxes—classic business email compromise blast-radius risks rather than a fleet-wide network intrusion.
Root cause
Account-level email unauthorized access (limited mailboxes)