NewsRansomware

World’s largest cruise company Carnival Corporation suffered from ransomware attack

The Carnival Corporation reported to the US Securities and Exchange Commission that the company suffered from an unnamed ransomware attack on August 15, 2020.

According to the documents that provided the company, attackers gained access to the systems of an unnamed subsidiary of the Carnival Corporation and encrypted files on the affected machines.

In addition, hackers have stolen files from the affected company’s network.

“As a result, it is believed that attackers could have gained access to the personal data of some employees and customers”, – said Securities and Exchange Commission representatives.

The cruise company is already investigating the incident with the assistance of law enforcement agencies. The Carnival Corporation has not yet disclosed any technical details about the incident, nor has it disclosed which particular ransomware was behind the attack.

At the same time, experts from Bad Packets told journalists of Bleeping Computer that Carnival Corporation could be hacked due to the CVE-2019-19781 vulnerability, which affects a number of versions of Citrix Application Delivery Controller (ADC), Citrix Gateway, as well as two old versions of Citrix SD-WAN WANOP.

“Not surprising given they had multiple Citrix servers vulnerable to CVE-2019-19781. CVE-2020-2021 could be another initial vector of compromise as well”, — tweeted by Bad Packets.

This problem was discovered at the end of 2019, and even then, analysts warned that more than 80,000 vulnerable servers could be found in the public domain, that is, the problem threatened tens of thousands of companies from 158 countries.

In addition, according to experts, the problem could lie in the CVE-2020-2021 vulnerability found in PAN-OS, an operating system running on firewalls and corporate VPN devices manufactured by Palo Alto Networks.

Reference:

Carnival Corporation is currently the world’s largest multinational cruise tourism company. It inlcudes over 20 subsidiary cruise lines including Carnival Cruise Lines, Princess Cruises, Holland America Line and Seabourn Cruise Line, P&O Cruises, Cunard Line, Ocean Village, AIDA Cruises, Costa Cruises and P&O Cruises Australia.

The Carnival Corporation owns more than 600 ships and employs 150,000 people serving more than 13,000,000 people annually.

Let me remind you that specialists from Palo Alto Networks also talked about attacks on Gulf shipping companies.

Regarding ransomware, 2020 is not only the year of the coronavirus epidemic, but also a real ransomware epidemic: MaxLinear chipmaker became a victim of ransomware, the Bank of Costa Rica suffered from the attack, ransomware operators even attack COVID-19 vaccine manufacturers, and this is only a small part known attacks. This difficult year is still far from finish.

Sending
User Review
0 (0 votes)
Comments Rating 0 (0 reviews)

Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Sending

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Back to top button