Jump to content

HAL Data Breach


Recommended Posts

I was on the HAL website this morning and checked out the Coronavirus updates as well as some other things.  Just now, I went back to the HAL website and noticed another notification about a "privacy event" (right below the Coronavirus updates):  https://www.hollandamerica.com/en_US/news/public-notice-privacy-event.html  I don't believe this notification was there this morning.  Anyway, I wanted to bring it to everyone's attention so that they can monitor their credit scores as recommended by HAL.

 

 

  • Like 1
  • Thanks 4
Link to comment
Share on other sites

9 minutes ago, Alberta Quilter said:

I was on the HAL website this morning and checked out the Coronavirus updates as well as some other things.  Just now, I went back to the HAL website and noticed another notification about a "privacy event" (right below the Coronavirus updates):  https://www.hollandamerica.com/en_US/news/public-notice-privacy-event.html  I don't believe this notification was there this morning.  Anyway, I wanted to bring it to everyone's attention so that they can monitor their credit scores as recommended by HAL.

 

 

Certainly was not there this morning.  Thanks for bringing it to our attention.

  • Like 1
Link to comment
Share on other sites

Did they just post this info this morning concerning a data-breach event that apparently occurred in the timeframe of 4/11/19-7/23/19?  Or is there a more up-to-date link concerning a more recent event?

Edited by Av8rix
Link to comment
Share on other sites

I believe they did just post the notification of the breach that occurred last year as you note.  I didn't see that notification this morning when I checked on the coronavirus update and another poster above confirmed that it was not there this morning.

Link to comment
Share on other sites

2 hours ago, Alberta Quilter said:

I believe they did just post the notification of the breach that occurred last year as you note.  I didn't see that notification this morning when I checked on the coronavirus update and another poster above confirmed that it was not there this morning.

This will be another kick in the teeth to CCL stock prices.  

 

Thanks for the heads up AQ...hopefully no one here is affected.  I did look at both Carnival and Cunard websites and couldn't see the same notification

Edited by CruisingAndDiving
Link to comment
Share on other sites

So, cutting through the hype....this sounds like a Carnival Corp. data breach.

 

For all the cyber security experts posting here...what should they have done? Be very specific...as it might be important on your future job applications. 

  • Like 2
  • Haha 1
Link to comment
Share on other sites

I remember last year I had an unauthorized charge from Princess for $200. I called Chase and they immediately closed the account and sent me a new card. Very inconvenient. Now I know where it came from. 

Link to comment
Share on other sites

Sure looks like they are using the Corona Virus to hide this notification. Geez. Happened a while back and they just post about it now? Sounds pretty low risk if it's just a matter of a few employee email accounts being compromised. I don't imagine that they are emailing around usernames/passwords. @CruiserBruce - security is a huge topic covering everything from physical security, firewalls, remote access practices, employee training on social engineering issues, etc. No one is going to reply with a detailed plan on what got missed by HAL. HAL probably responded with many pages of documentation on security enhancements to improve things, but even then, it's a constant improvement process that has no one answer.

  • Like 1
Link to comment
Share on other sites

7 hours ago, iwantsomesun said:

Sure looks like they are using the Corona Virus to hide this notification. Geez. Happened a while back and they just post about it now? Sounds pretty low risk if it's just a matter of a few employee email accounts being compromised. I don't imagine that they are emailing around usernames/passwords. @CruiserBruce - security is a huge topic covering everything from physical security, firewalls, remote access practices, employee training on social engineering issues, etc. No one is going to reply with a detailed plan on what got missed by HAL. HAL probably responded with many pages of documentation on security enhancements to improve things, but even then, it's a constant improvement process that has no one answer.

I am very aware of how security works. The number of second guessing experts..."they should of", "no excuse" type comments show a lack of understanding of how the bad guys operate.

  • Like 1
Link to comment
Share on other sites

   Right now I'm royally PO'd with HAL for the secretive nature of this notice.   We have a trip planned within a month and today I got a notice that says NONE of my info that was inputted when I made the reservation is in their data base.   EVERYTHING..........all passport and Nexus info; emergency contacts and their info--every stinking thing of mine that HAL had-------was taken.   

Edited by thyme2go
wording
Link to comment
Share on other sites

@thyme2go, could you copy & paste their letter to you about the breach here?

( MINUS your personal information of course 😉

 

re: 

 

>>  I got a notice that says NONE of my info that was inputted when I made the reservation is in their data base.   EVERYTHING..........all passport and Nexus info; emergency contacts and their info--every stinking thing of mine that HAL had-------was taken.   

Link to comment
Share on other sites

SempreMare,  HAL did not send me a notice with the missing info AND the breach in one email.   I am the one who put that together as the email I received had the title "Missing  Information" which is not that unusual and I expected there to be one or two piece's of info missing........when I looked for the missing info i I discovered that everything when I made the reservation was no longer there.   

Two of us are traveling and these were the lists (slightly different) under each name.      

 

Person #1

Emergency Contact Name
Emergency Phone
Emergency Full Address
Passport Number
Country Of Passport
Issuance
Passport Issue Date
Passport Expiry Date
Invalid Travel Document
Type

 

Person #2:

Country Of Residence
Emergency Contact Name
Emergency Phone
Emergency Full Address
Citizenship
Passport Number
Country Of Passport
Issuance
Passport Issue Date
Passport Expiry Date
Country Of Birth
Invalid Travel Document
Type
Us Address While In Us

 

I don't presume to be on top of everything but it just seemed odd to me to be asking for  info that should have already been in their system..........especially after the breach.  

Edited by thyme2go
Link to comment
Share on other sites

Nope, that's not how it works, unless it's a ransomware attack. Where the intent is to extort money from HAL.

 

What is more likely is that HAL deleted the data themselves because they couldn't trust that the hacker hadn't modified it. Or more specifically they wiped the computers that the hacker access to. It usually simpler to hit it with a big hammer, especially when it's relatively easy to get the lost info from other "secure" sources.

Link to comment
Share on other sites

Thanks mrmoviezombie for the plausable explanation...........

I didn't assume it was literally stolen but this is too weird given both things happened--security breach and empty data in my account.   I have to admit that HAL is not inspiring a lot of confidence right now............and inputting data is not fun either!

 

Link to comment
Share on other sites

3 hours ago, thyme2go said:

SempreMare,  HAL did not send me a notice with the missing info AND the breach in one email.   I am the one who put that together as the email I received had the title "Missing  Information" which is not that unusual and I expected there to be one or two piece's of info missing........when I looked for the missing info i I discovered that everything when I made the reservation was no longer there.   

Two of us are traveling and these were the lists (slightly different) under each name.      

 

Person #1

Emergency Contact Name
Emergency Phone
Emergency Full Address
Passport Number
Country Of Passport
Issuance
Passport Issue Date
Passport Expiry Date
Invalid Travel Document
Type

 

Person #2:

Country Of Residence
Emergency Contact Name
Emergency Phone
Emergency Full Address
Citizenship
Passport Number
Country Of Passport
Issuance
Passport Issue Date
Passport Expiry Date
Country Of Birth
Invalid Travel Document
Type
Us Address While In Us

 

I don't presume to be on top of everything but it just seemed odd to me to be asking for  info that should have already been in their system..........especially after the breach.  

Are you sure this request is actually from HAL?  I would call them direct and ask them about it.

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
 Share

  • Forum Jump
    • Categories
      • Welcome to Cruise Critic
      • New Cruisers
      • Cruise Lines “A – O”
      • Cruise Lines “P – Z”
      • River Cruising
      • ROLL CALLS
      • Cruise Critic News & Features
      • Digital Photography & Cruise Technology
      • Special Interest Cruising
      • Cruise Discussion Topics
      • UK Cruising
      • Australia & New Zealand Cruisers
      • Canadian Cruisers
      • North American Homeports
      • Ports of Call
      • Cruise Conversations
×
×
  • Create New...