Carnival Corporation confirms social-engineering breach affecting nearly 6 million people
The world's largest cruise operator began notifying almost 6 million people that an attacker who socially engineered an employee had copied names, contact details, dates of birth and passport and driver's license numbers, weeks after ShinyHunters leaked data it claimed to have stolen.
- Victim
- Carnival Corporation
- users
- 6.0M
On 27 May 2026, Carnival Corporation, the world's largest cruise company, began notifying customers of a cybersecurity incident and told the Maine Attorney General that 5,995,277 people were affected. Carnival had already disclosed data breaches in 2019, 2020 and 2021.
What happened
According to Carnival's notice, an attacker used social engineering to trick an employee into granting access to part of the company's IT environment; Carnival identified the activity on 14 April 2026. By 22 April, the intruder had used a compromised account to reach a "limited portion" of Carnival's systems and copy personal data before being cut off.
The extortion group ShinyHunters claimed the attack, said it had taken 8.7 million records, and published the data in late April after Carnival did not pay. Breach-notification service Have I Been Pwned later linked about 7.5 million accounts in the leak to the Holland America Mariner Society loyalty program.
What was exposed
The affected information may include names, postal and email addresses, phone numbers, dates of birth, gender, geographic location, loyalty program details and government-issued ID numbers such as driver's license and passport numbers. Carnival offered affected U.S. customers 24 months of free credit monitoring.
Why it matters
The incident follows the 2026 ShinyHunters pattern of phone- or chat-based social engineering against employees rather than technical exploits. For a cruise operator, the inclusion of passport numbers and travel loyalty data makes the stolen records especially useful for targeted phishing and identity fraud aimed at frequent travelers.
Timeline
Carnival identifies that an attacker socially engineered an employee into granting access to part of its IT systems.
Using a compromised account, the attacker accesses a limited portion of Carnival's systems and copies personal data before being blocked.
Carnival sends breach notification letters and reports 5,995,277 affected people to the Maine Attorney General.
Sources
- securityweek.comhttps://www.securityweek.com/carnival-data-breach-exposed-6-million-people/
- malwarebytes.comhttps://www.malwarebytes.com/blog/data-breaches/2026/05/carnival-confirms-data-breach-impacting-nearly-6-million
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/05/28/carnival-corporation-data-breach/