Site navigation

Why Was Carnival Cruise Lines Hit With a $5m Fine?

Michael Behr

,

Carnival Cruise fine
Despite being hit by a series of attacks, New York authorities found that Carnival had not implemented proper cybersecurity procedures in their aftermath.

Carnival Corporation, one of the world’s biggest cruise line operators, was hit with a $5 million fine in the US for violating cybersecurity laws.

The company paid the penalty to the state of New York for violating its cybersecurity regulations.

According to the state’s Department of Financial Services (DFS), the company had been the subject of four cybersecurity events between 2019 and 2021, including two ransomware attacks

“A data breach exposing personal data allows bad actors to, among other things, commit identity theft, which can have significant repercussions on an individual’s financial health. It is critical that companies take appropriate action to protect consumers’ personal information,” said Superintendent Adrienne Harris.

Among the cyberattacks it was fined for was one that took place in March 2020. The attackers gained access to several employee email accounts, revealing personal information, including names, email addresses, IDs, financial and health information of guests on the ships.

The company said that it shut down the attack and prevented further unauthorised access before hiring a cybersecurity firm to investigate the attack.

Another cyber-attack followed in August 2020, when Carnival’s systems were hit by ransomware.

Not only were the attackers able to encrypt its IT systems, but they also downloaded data, which a regulatory filing said included personal data of guests and employees.

According to the New York DFS investigation, Carnival failed to implement multi-factor authentication (MFA), did not to promptly report the first cybersecurity event, and failed to conduct adequate cybersecurity training for their personnel.

This meant that the company’s cybersecurity compliance certifications for the calendar years 2018 through 2020 were improper. Furthermore, failing to implement MFS left Carnival’s IT systems and their consumers’ non-personal information extremely vulnerable to threat actors.


Recommended


Commenting on the Carnival cruise fine, CEO of UK cybersecurity firm MIRACL Rob Griffin said: “Conventional multi-step, multi-factor authentication typically relies on a user having a mobile phone to provide secure access to corporate systems or applications.

“This is frequently not possible in environments such as ships, shops and factory floors, hospitals and laboratories where mobiles may be banned. The result has been to bypass MFA altogether, which has led to an increased frequency of breaches and ransomware incursion.

“There’s no longer an excuse for organisations not to implement MFA, as new systems are emerging that can cater to these types of environments, enabling a far faster, single-step MFA – but crucially without the need for a mobile.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data