Menu
Browse

Cyber Incident Victim: Carnival Corporation

Date

Apr 2026

Location

United States of America

Status

Unknown

Updated

2026-07-18 01:08

Timeline
Occurred
Apr 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Carnival Corporation disclosed a breach affecting nearly six million individuals after a social engineering attack compromised an employee account and granted unauthorized access to part of its IT environment. The compromised data included names, addresses, email addresses, phone numbers, dates of birth and government‑issued identification numbers such as driver’s license and passport numbers, with some records linked to the Holland America Mariner Society loyalty program. The company confirmed the breach after detecting unauthorized activity, engaged third‑party security experts, notified law enforcement and began sending notification letters to affected individuals. Carnival offered two years of complimentary credit monitoring to eligible U.S. individuals and added additional security monitoring and monitoring controls. The extortion group ShinyHunters claimed responsibility, though Carnival has not confirmed the claim.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

Carnival Corporation disclosed on May 27 2026 that its security team had detected unauthorized activity involving an employee account on April 14 2026, tracing the intrusion back to a social engineering attack that gave an unauthorized actor access to a limited part of its IT environment on April 10 2026. The company’s investigation, completed on April 22 2026, confirmed that personal information had been copied, and a filing with the Maine Attorney General’s office on May 27 listed 5,995,277 affected individuals. Carnival publicly confirmed the breach on May 27, stating that the incident involved a social engineering ploy on a single user account and that it had immediately blocked the activity, engaged third‑party security experts and alerted law enforcement. The company also noted that it had not publicly confirmed responsibility for the attack, although the extortion group ShinyHunters claimed responsibility in April 2026, a claim that Carnival has not verified and that the FBI has warned victims not to pay.

Cyber Incident Image

The data exposed in the breach included names, addresses, email addresses, phone numbers, dates of birth and government‑issued identification numbers such as driver’s license and passport numbers, with the specific data elements varying by individual. Have I Been Pwned’s analysis of the data leaked by ShinyHunters reported 8.7 million records containing 7.5 million unique email addresses, many of which were tied to Holland America’s Mariner Society loyalty program and included names, dates of birth, email addresses, genders, geographic locations, salutations and loyalty program details. Carnival’s 2025 annual report indicated it served roughly 13.5 million guests in 2025 across its fleet of 90 ships, which includes the Carnival Cruise Line, AIDA, Costa, Cunard, Holland America, P&O and Princess brands. Prior to this incident, Carnival had disclosed breaches in March 2020 and June 2021 after attackers accessed employee email accounts, and ransomware events in August 2020 and December 2020 that exposed personal information tied to customers and employees.

In response, Carnival said it sent notification letters to affected individuals, expressed regret for any concern caused and emphasized that protecting the privacy and security of personal data remains a priority, noting that it has added new layers of security and monitoring atop its existing protections and will continue advancing its defenses against evolving threats. The company also stated it is conducting a thorough and time‑consuming analysis to determine exactly what personal information was compromised and that it is offering individuals in the United States two years of complimentary credit monitoring through its preferred third‑party vendor, TransUnion. Carnival included a frequently asked question in an online notice for those it could not reach by mail, asking “Why am I just finding out about this?” Some recipients reacted on the Reddit forum r/CarnivalCruiseFans, with one commenter noting that “at this point our data has been out for quite some time,” while others said they would prefer compensation or a future cruise voucher rather than the offered credit monitoring.

Sources
Sources available to members
6 sources