1k Data Breaches Later, the Disclosure Lag Is Worse
What they're not telling you: 1,000 Breaches and Counting: The 43-Day Silence That Nobody's Enforcing Carnival Corporation waited 43 days to tell 7.5 million people their personal data had leaked. That's the metric that matters. Not the breach itself—corporate networks get compromised constantly in 2024.
What the Documents Show
The scandal is the lag. Carnival learned about the ShinyHunters attack on April 19. The hacker collective published the stolen files publicly on April 24. Industry observers noticed immediately. By late April, 8.7 million customer records containing names, dates of birth, email addresses, loyalty program details, and physical location data were already circulating through dark-web forums, Telegram channels, and public hosting sites.
Follow the Money
Carnival said nothing until May 27. Six weeks of silence while victims remained completely unaware their information was for sale. This isn't an outlier. Troy Hunt, who maintains Have I Been Pwned, documented the 1,000th data breach this week and noted something that should alarm anyone paying attention to corporate accountability: disclosure lag times are increasing, not shrinking. We've had privacy regulations—GDPR since 2018, CCPA since 2020—that explicitly require prompt breach notification. Yet companies are sitting on breach information longer, not shorter.
What Else We Know
The regulatory answer is supposed to be state attorneys general and the Federal Trade Commission. The FTC has authority over unfair and deceptive practices. Every state has a data breach notification law. California's Attorney General could theoretically pursue Carnival for violating the 45-day notification window under California law. Yet here we are, watching a major multinational cruise operator burn a 43-day clock while regulators remain functionally invisible. Carnival Corporation is a $6 billion market-cap company that operates three cruise lines serving over 10 million passengers annually.
Primary Sources
- Source: Hacker News
- Category: Corporate Watchdog
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.