Security notice
Quarterdeck · Last updated: 31 August 2026
Between 10 and 18 August 2026, an unauthorised third party accessed one of our internal systems and copied data relating to Quarterdeck.
We discovered this on 19 August, shut the affected system down the same day, and reported it to the relevant authorities. Our investigation is continuing.
The Quarterdeck platform itself was not compromised. The intrusion was confined to a single internal reporting tool that had access to our databases. There is no evidence of unauthorised access to any of our websites or applications, and no evidence that any account has been taken over. No data was changed or deleted — the intruder was only able to read. Our services have operated normally throughout.
Quarterdeck Life Ltd manages the people who work the trips and holds your record. It is a separate company from the brands running the trips themselves, which is why this notice comes from Quarterdeck rather than from a brand you may have worked under. If you also travelled as a guest, that is a separate record and a separate notice.
Change your Quarterdeck password
Quarterdeck account passwords were among the data copied. They were not stored in readable form, but the method protecting them is outdated by current standards and can be reversed with the computing power available today. Treat your old password as known to someone else.
If you reused that password anywhere that matters — email, banking, cloud storage — change it there first, then change it here. Whoever holds this data also holds your email address, and that combination is what makes an attempt on your other accounts worth trying.
Your data, in your account
You can now download everything we hold about you, or delete your account and the data we are not required to keep, from your profile page. Both take effect immediately and neither needs us. Log in, open Edit profile, and use the red Delete my account button at the bottom. It shows you what we hold, category by category, before anything happens.
The other button on that page does not delete anything. Go off radar only deactivates — it stops reminder emails and takes you off active crew lists, and erases nothing.
Deletion is immediate and cannot be undone, so take the download first if you want a copy. A confirmed course or assignment still to come keeps the button disabled until its last day. How the download works · What deletion removes · Can I get my account back?
WHAT WAS AFFECTED
This varies from person to person, and included some or all of:
- Names, email addresses, phone numbers and postal addresses
- Passport numbers, dates of birth, place and country of birth, nationality and sex as recorded on the document — collected for work, travel and border requirements
- Next-of-kin details — the name and contact details given as an emergency contact
- Account passwords — see the section above, because this one needs action from you
- Payment records — the amounts, dates and status of payments
- Stored card references — card type, expiry and last four digits
- For a smaller group, bank account details — account holder name, address, phone, account number, IBAN, SWIFT and routing number
- Password-recovery codes — every code copied had already expired before the intrusion ended, so none could be used
If you received an email from us, it lists what was in your record specifically. Keep it — it is the accurate account for you, and it stays in your inbox whatever you decide to do with your account. What was copied in the incident?
If your bank details were included
Your notice says so explicitly if this applied to you. These details do not let anyone take money from your account, but they make a convincing approach possible — the common fraud is someone telling a person who pays you that your details have changed. Tell your bank, and ask anyone who pays you to confirm by voice before changing where they send money.
WHAT WAS NOT AFFECTED
-
The documents you uploaded — passport copies, licences, certificates and CVs. They sit in separate file storage that could not be listed, and the two tables that would have given away individual file addresses were not among the eleven copied.
The full reasoning - Card security codes. We have never stored CVV or PIN numbers, so none could be taken.
- Usable card numbers. The card references we hold are gateway tokens and cannot be used to take a payment.
- Account passwords — see the section above, because this one needs action from you
- Payment records — the amounts, dates and status of payments
- Stored card references — card type, expiry and last four digits
- For a smaller group, bank account details — account holder name, address, phone, account number, IBAN, SWIFT and routing number
- Password-recovery codes — every code copied had already expired before the intrusion ended, so none could be used
Separately from this incident, an older storage location was found to be configured so that its contents could be reached without authentication. It held documents uploaded in earlier years, and it was closed on 21 August. Access logging was not switched on for it, so we cannot determine whether anything was ever accessed through it — we would rather say that plainly than tell you nothing was. The current storage was never configured that way. If you uploaded documents before 2024 and want to know what is held for you, ask us.
WHAT TO DO?
First: change your password — anywhere you reused it first, then here. That is the one step this incident genuinely requires of you.
Everyone: be alert to unexpected emails, calls or messages about this incident or your work with us. We will never send you a password reset link you didn’t request, never ask you to reply with card or bank details, and we are not making outbound phone calls about this. Anything that does is not us — go to quarterdeck.co by typing it into your browser, not by following a link.
If your passport details were included: put a fraud alert on your credit file. It is free from the credit reference agencies and it stops most new accounts being opened in your name. Query any application, account or letter you did not expect. If you find something, report it to your national fraud reporting service — Action Fraud in the UK, the police elsewhere. Do I need to replace my passport?
If you want the data gone: use the delete button above. It takes effect immediately. More of a crew record carries a legal retention period than a guest record does, and the dialogue tells you exactly what stays. The full list of steps worth taking
WHAT ACTIONS HAVE BEEN TAKEN
- The affected system was shut down the same day it was discovered, taken off the internet and permanently decommissioned.
- All database credentials have been replaced, and access is now tightly restricted.
- The unauthorised access the intruder had created has been identified and removed.
- The older storage location described above was closed on 21 August, and file versioning has been enabled.
- Password storage and password recovery have been strengthened, and the way recovery codes are generated has been replaced.
- Since 28 August, everyone with an account can download their data and delete it directly from their profile, without asking us.
- Logs and evidence have been preserved for the investigation, and we are working with the authorities and our insurers.
Further work is under way, including a programme to reduce how much historical personal data we hold at all. Why did you still have my data after I stopped working with you?
Are you contacting people individually?
Yes. We are writing to everyone affected for whom we hold a working email address, explaining what was included in their own records.
Some older crew records do not have a working email address on file, so we cannot reach those people directly. If you have worked with us and do not hear from us, please treat this page as your notification and follow the guidance above.
Common questions
- Do I need to change my Quarterdeck password?
- What was copied in the incident?
- Were my passport or licence documents taken?
- My bank details were included — what should I do?
- How do I get a copy of my data?
- How do I close my account and delete my data?
- Can I get my account back after deleting it?
- How quickly will you delete my data?
- Do I need to replace my passport?
- What should I do to protect myself?
- Why did you still have my data after I stopped working with you?
- Will you compensate me?
- Can I speak to someone on the phone?
- Have you reported this to the data protection authorities?
Questions
If the help centre does not answer it, write to notice@quarterdeck.co. We cannot send personal data out by email — we have no way to confirm who is behind an email address, which is why the download sits behind your account. If you cannot get into your account, write to us and we will verify you another way.
Quarterdeck Life Ltd reported this to the UK Information Commissioner’s Office under reference IC-556590-F4V7. You have the right to complain to your own data protection authority at any time, and raising something with us first does not limit that right.
We will update this page as our investigation continues.