A cybersecurity incident at cruise operator Carnival Corp. (NYSE:CCL) exposed sensitive personal information after attackers gained access through a compromised employee account in a social engineering attack.

Cyberattack Exposed Personal Data Through Employee Account

On Wednesday, Carnival said it detected unauthorized activity in April after cybercriminals used social engineering tactics to deceive an employee and gain access to certain data through the worker's account.

The company said the incident resulted in the exposure of some personal information belonging to affected individuals, including names, physical addresses and government-issued identification numbers.

Carnival said it quickly blocked the unauthorized access and brought in third-party cybersecurity specialists to investigate the incident and assess its scope.