{
  "id": 6680867,
  "title": "A real Carnival Cruise Line email was serving customers malware",
  "url": "https://urgent.news/2026/09/11/a-real-carnival-cruise-line-email-was-serving-customers-malware",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-11T01:07:57.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/tuxxin/a-real-carnival-cruise-line-email-was-serving-customers-malware-4jle"
  },
  "original_language": "en",
  "account": "A genuine Carnival Cruise Line booking confirmation email led customers to malware. The email passed authentication checks and appeared legitimate. The issue stemmed from a promotional domain that had lapsed and was later re-registered by someone else. Carnival regained control of the domain on August 26th, 2026, and the malicious link was identified and removed the following day. When traversed, the link directed users to a fake-security page that prompted a download. The same link yielded different outcomes depending on the visitor's device and network, with scanners and datacenter IPs landing on a benign page, while real browsers experienced malware installations, scareware, and fullscreen lockers. The domain resolved to a monetization service, and the content displayed varied based on the visitor's actions, with automated clients receiving a compliant parking page and real browsers being routed to an advertiser. The advertiser network behind the domain changed between visits, and each removal required individual verification. Despite the removals, the entry domain remained live, and the email link continued to redirect users until Carnival re-acquired the domain on August 26th. The traffic split could be attributed to the sorting of traffic based on its value, with automated checks receiving compliant pages and human users being routed further down. The specific advertisers and commercial terms were not disclosed in the report.",
  "summary": "A genuine Carnival Cruise Line booking confirmation routed customers to malware. The mail was authentic and passed SPF, DKIM and DMARC. The failure was a promotional domain Carnival had let lapse, still linked from live marketing mail, re-registered by someone else and wired into a redirection network. Carnival re-acquired the domain on August 26th, 2026, and I verified the vector dead the next…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}