Last Update: 08/01/2026 at 1:00 PM EST

Carnival Breach Exposes Passenger ID Data

Coverage from Reuters, BleepingComputer, and others

Articles

75

Active Days

97

The Topic

Carnival Breach Exposes Passenger ID Data topic image

Carnival Corporation disclosed that an attacker used social engineering to compromise an employee account and access a limited portion of its IT environment in April 2026. The company later determined that personal information had been copied, potentially affecting nearly 6 million people, with exposed data varying by individual and including government-issued identification details. Carnival is notifying affected individuals, offering U.S. customers two years of credit monitoring, and investigating the incident with outside experts, while ShinyHunters has claimed responsibility without public attribution from Carnival.

First Article: 04/19/26

Latest Article: 07/24/26

Summary

  • An attacker used social engineering to gain access through a Carnival employee account and reach a limited portion of the company’s IT systems.
  • Carnival determined that personal information was copied, including names, contact details, dates of birth, and, for some individuals, driver’s license or passport numbers.
  • Regulatory filings and company notifications indicate that nearly 6 million people may be affected, including up to 800,060 Texans.
  • ShinyHunters claimed the breach and attempted extortion, but Carnival has not publicly attributed the incident to the group.
  • Carnival blocked the unauthorized activity, engaged third-party investigators, notified affected individuals, and offered eligible U.S. customers two years of TransUnion credit monitoring.
  • The incident creates an ongoing risk of identity theft and fraud, while Carnival continues to determine exactly which data belonged to which individuals.

History

07/28/2026

The update adds that ShinyHunters attempted extortion and that Carnival still has not publicly attributed the breach to the group. It also sharpens the exposure picture by naming the Texas filing and the scale of Texans potentially affected.

07/27/2026

The update adds concrete disclosure details around the breach’s scope, affected data, and remediation, while dropping earlier emphasis on ShinyHunters-driven extortion and litigation. The story is now centered more on confirmed exposure of sensitive identifiers and official notification actions, including a large Texas resident count.

Full History

Featured

Timeline: 97 Days

Apr 19May 10May 24Jun 14Jun 28Jul 19

Additional Articles

⭐⭐⭐⭐⭐

The Record / Daryna Antoniuk05-28-2026
Carnival confirmed in May that a ShinyHunters-linked April attack led to copying passenger passport and driver license data after an employee account compromise.
WFAA06-23-2026
Texas Attorney General Ken Paxton announced an investigation of Carnival Corporation in Austin after an April 2026 breach exposed personal data affecting 800,060 Texas residents.
National Law Review / William Fife06-22-2026
Texas Attorney General Ken Paxton announced an investigation into Carnival Corporation after an April 2026 social-engineering data breach exposed about six million people.
Aol06-01-2026
Carnival Corporation disclosed an April data breach in U.S. customer filings, began May 27 notifications, and partnered with TransUnion for two years of credit monitoring.
Aol / Drew Pittock06-02-2026
Carnival Corporation disclosed on May 27 a data breach discovered April 14 in the USA|Maine, involving social engineering and exposure of passenger identity documents.
Help Net Security / Sinisa Markovic05-28-2026
Carnival Corporation disclosed a phishing-driven employee account compromise on April 14, 2026, with Maine breach notification for 5,995,277 people starting May 27.
NeuraCyb Intel / Ashish S05-31-2026
Carnival Corporation reported a social-engineering data breach discovered April 14, 2026, with Maine Attorney General notification covering 5,995,277 affected individuals.
WPGA / Jordan Gartner05-31-2026
Carnival Corporation reported April 14 unauthorized access via a social-engineered employee account compromised, exposing passport and driver license data and prompting a Maine Attorney General notice for 5,995,277 people.
97.9 The Box06-01-2026
Carnival Corporation disclosed April 14 breach impacts on millions, including Texas cruise passengers, after a targeted employee-access attack.
Woodlands Online06-22-2026
Ken Paxton announced an investigation in Texas into Carnival Corporation after an April 2026 data breach exposed personal information for 800,060 Texans.
Texas Attorney General06-22-2026
Texas Attorney General Ken Paxton announced an investigation into Carnival Corporation after an April 2026 breach exposed personal information for 800,060 Texans.
KETK06-23-2026
Ken Paxton investigated Carnival Corporation in Texas after an April data breach exposed personal information of 800,060 Texans, with breach notice submitted 44 days later.
Credit and Collection News06-22-2026
Texas Attorney General Ken Paxton launched a data-breach investigation into Carnival after a social-engineering incident compromised an employee account and exposed 800,060 Texas residents.
Ship Universe07-23-2026
Cruise operators are advised to secure passenger identity, payment, and guest app systems to prevent fleetwide privacy harms after a major data breach.
930 WFMD Free Talk05-30-2026
Carnival Corporation disclosed an April data breach tied to social engineering and offered TransUnion credit monitoring after exposure of nearly 6 million customers’ personal data.
Ksstradio06-22-2026
Ken Paxton launched a Texas investigation on June 22, 2026 into Carnival Corporation after a 2026 breach exposed customer data and notification occurred 44 days later.
Complex05-31-2026
Carnival Cruise Line disclosed in 2020s timeframe that social engineering compromised an employee account in April, exposing names, addresses, and government IDs, with U.S. credit monitoring offered via TransUnion.
Texas Border Business06-24-2026
Ken Paxton announced a Texas investigation into Carnival Corporation after a socially engineered employee-account breach exposed personal information for hundreds of thousands of Texas consumers in April 2026.
Malwarebytes / Pieter Arntz05-28-2026
Carnival Corporation notified Maine and other audiences in 2026 after an April 2026 intrusion copied personal data from Carnival IT systems.
Dallas Express06-22-2026
Ken Paxton announced a Texas investigation into Carnival Corporation after an April 2026 breach exposed consumer information for 800,060 Texas residents.
Safestate05-28-2026
Carnival Corporation disclosed a 5,995,277-customer data breach beginning April 10, 2026, after social-engineering credential compromise and notifications starting May 27.
FOX 5 DC / Chris Williams05-29-2026
Carnival Corporation began notifying people on May 27, 2026 after a April 14 social-engineering intrusion exposed personal data, offering TransUnion credit monitoring in the U.S.
Lifehacker05-29-2026
Carnival Corporation notified Maine-relevant consumers in 2026 after a April network intrusion exposed personal and loyalty data for about 6 million people.
Security Affairs / Pierluigi Paganini05-28-2026
Carnival Corporation notified Maine and nearly 6 million people after social engineering enabled an employee account compromise and exposure of identity data starting April 14, 2026.
KXAN / Abigail Jones06-23-2026
Ken Paxton is investigating Carnival in Texas after a reported April data breach exposed personal information of 800,060 Texas consumers, with notification filed 44 days later.
The National CIO Review / Emily Hill05-28-2026
Carnival Corporation reported April 2026 discovery of a social-engineering-driven breach after attackers accessed internal systems and copied data affecting 5,995,277 individuals.
USA Today06-02-2026
Carnival Corporation disclosed a passenger data breach on May 27 after a social engineering intrusion detected April 14 and customer data exposure determined April 22.
Chinook Observer07-24-2026
KND Complex Litigation and Hammerco Lawyers LLP filed a proposed Canadian class action in 2026 over Canadian Tire exposure of more than 40 million records in a 2025 breach.
Daily Hive06-19-2026
Slater Vecchio filed a Canadian class action in British Columbia on June 17, 2026, alleging Carnival Corporation mishandled an April 14 breach involving exposed personal identifiers.
Pluang05-28-2026
Carnival Corporation detected an April 14, 2026 social engineering attack exposing personal data for about 5.99 million people, leading to class action investigation.
Morgan & Morgan07-07-2026
Carnival Corporation disclosed a 2026 incident on April 14, 2026, where social engineering enabled unauthorized access and illegal copying of customer personal data potentially affecting about six million people.
Almeida Law Group05-28-2026
Carnival Corporation disclosed a phishing-driven data breach discovered April 14, 2026 and linked to Mariner Society after ShinyHunters extortion, with notifications sent May 27, 2026.
Boerne Star06-24-2026
Texas Attorney General Ken Paxton announced an investigation into Carnival after an April 2026 breach exposed personal information of about 800,000 Texas consumers.
Holzberg Legal04-28-2026
Yvonne Vasquez filed a class action against Carnival Corporation in Florida, alleging a 2026 cybersecurity failure exposed unencrypted personal data for about 8.7 million people.

⭐⭐⭐

Morningstar06-01-2026
Carnival Corporation disclosed a reported April 2026 data breach affecting nearly 6 million travelers after social engineering targeted employee accounts.
Houston Public Media / Kyle McClenagan06-01-2026
Carnival Inc. disclosed an April 14 unauthorized-access breach that the Texas Attorney General says may have exposed personal data for up to 800,060 Texans.
The Register / Carly Page04-24-2026
Have I Been Pwned flagged 7.5 million email addresses tied to Carnival Corporation while the company reported a limited phishing compromise.
Insurance Journal05-28-2026
Carnival Corp disclosed on May 27 that a compromised employee account in April exposed personal information including government-issued identification numbers, after social engineering access.
Top Class Actions05-25-2026
Zachary Pottle filed a Florida federal class action on April 22, 2026, alleging Carnival failed to notify customers after ShinyHunters stole over 8.7 million PII records in a ransomware breach on April 18, 2026.
Claim Depot05-28-2026
Carnival Corporation disclosed in 2026 a social-engineering-driven data breach affecting 5.99 million U.S. residents and began California filings and consumer notifications with TransUnion credit monitoring.
Benzinga / Ananya Gairola05-28-2026
Carnival Corp. reported an April employee-account compromise using social engineering, exposing personal data and leading to May 27 notifications and TransUnion identity protection for U.S. customers.
WECT / Jordan Gartner05-31-2026
Carnival Corporation reported on an April 14 employee-account compromise after possible exposure of traveler passport and driver license numbers.
WBRZ05-31-2026
Carnival Corporation reported an April data breach discovered after unauthorized access to an employee account exposed sensitive personal identifiers for nearly six million people.
Cruise Radio / Richard Simms04-24-2026
ShinyHunters allegedly accessed Carnival Corporation data and issued a ransom threat, while Carnival reported blocking unauthorized activity and notifying law enforcement.
IT CPE Academy05-29-2026
Carnival Corporation disclosed a data breach in the U.S. after ShinyHunters claimed access to Mariner Society loyalty data following a phishing compromise detected April 14, 2026.
KECI / Laura Freeman06-01-2026
Carnival Corporation notified nearly 6 million customers in a data breach announced after an April social engineering attack.
The State AG Report06-25-2026
Texas Attorney General Ken Paxton announced a Carnival Corporation investigation after an April 2026 data breach involving employee-account deception and consumer data exposure.
Lifehacker05-29-2026
Carnival Corporation disclosed a consumer data breach to Maine officials after April 10 exposure, notifying about 6 million people starting May 27 and offering TransUnion credit monitoring.
Cybersecurity Insiders / Jane Devry06-02-2026
Carnival Corporation reported a 6 million-cruiser data breach in response to social engineering that enabled unauthorized access to an employee-linked account.
CyberInsider / Alex Lekander04-19-2026
ShinyHunters threatened to leak alleged stolen data from Carnival Corporation by April 21, 2026 after Carnival detected suspicious phishing tied activity on one account.
ABC13 Houston06-01-2026
Carnival Corporation disclosed that a April social-engineering attack led to unauthorized access to passenger passport numbers and dates of birth.
KHOU06-23-2026
Texas Attorney General Ken Paxton announced an investigation into a Carnival Cruise Line cybersecurity incident affecting about 800,000 Texans, involving customer identity data.
WSMV 4 / Jordan Gartner05-31-2026
Carnival Corporation reported a April 14 incident after social engineering compromised an employee account, exposing identity data for 5.99 million people in a Maine Attorney General notice.
SRN News05-27-2026
Carnival Corp reported a April cybersecurity incident involving a compromised employee account, using social engineering to leak personal information and prompting May 27 TransUnion credit-monitoring offers.
KPRC Click2Houston05-31-2026
Carnival Corporation disclosed May 27 that a social-engineering attack in April may have exposed passport and driver's license numbers for some travelers, including Texas cruise passengers.
Security Magazine05-28-2026
Carnival Corporation confirmed a ShinyHunters ransomware data breach in April 2026 after social engineering compromised an employee device, affecting millions of customers.
WGME05-28-2026
Carnival Corporation filed a Maine Attorney General breach notice in connection with unauthorized employee-account activity affecting nearly 10,000 Mainers.
WGME05-28-2026
Carnival Corporation notified the Maine Attorney General's Office after unauthorized employee-account activity exposed personal data for nearly 10,000 Mainers.
WTAQ News Talk05-27-2026
Carnival Corp reported a May 27 disclosure of an April cybersecurity incident where social engineering enabled unauthorized access to personal data tied to an employee account.
FOX 9 Minneapolis-St. Paul / Chris Williams05-29-2026
Carnival Corporation notified affected individuals beginning May 27 after an April 14 social-engineering attack led to unauthorized access to parts of Carnival IT systems.
LiveNOW from FOX / Chris Williams05-29-2026
Carnival Corporation notified potentially affected individuals in May 2026 after an April 14, 2026 social engineering-driven breach exposed personal information including government ID numbers.
Cruise Hive / Melissa Mayntz04-24-2026
Carnival Corporation is investigating an extortion-related data breach claim listed by ShinyHunters after unauthorized activity was detected in a single user account, with a deadline expiring April 21, 2026.
Cruise Hive / Catie Kovelman04-30-2026
Between April 22-24, 2026, three plaintiffs filed class-action lawsuits in Florida against Carnival Corporation over an alleged ShinyHunters-linked breach and delayed notification.
Yahoo Travel / Helen Hatzis06-01-2026
Carnival Corporation disclosed a social engineering intrusion on an unspecified date that exposed passenger dates of birth and passport numbers.
Daily Express US06-02-2026
Carnival Corporation reported a cybersecurity breach discovered in 2026 after an April 2026 incident exposed personal information of nearly 6 million customers.
WHBL05-27-2026
Carnival Corp announced May 27 that an April employee-account compromise enabled social engineering, exposing personal data and triggering notification and TransUnion credit monitoring.
Daily Hive06-04-2026
Carnival Corporation reported a social-engineering attack on April 14, 2026, leading to unauthorized access and guest notifications with free credit monitoring.
WJXT News4JAX06-02-2026
Carnival Corporation notified customers in May 2026 about an April 2026 incident involving employee-account social engineering and offered TransUnion credit monitoring to U.S. customers.
ABC7 Bay Area06-01-2026
Carnival Corporation disclosed an April data breach after social engineering enabled unauthorized system access, exposing passenger dates of birth and passport numbers.
AOL.com06-02-2026
Carnival Corporation disclosed a social-engineering cyber breach discovered April 14 and confirmed customer data compromise by April 22, with notifications starting May 27.
Cision PR Newswire05-27-2026
Carnival Corporation issued May 27, 2026 data-breach notifications after April 2026 social engineering compromised an employee account and exposed personal identifiers.
Holzberg Legal04-28-2026
Ashley Cole filed a class action in Southern District of Florida against Carnival Corporation alleging delayed breach notice after alleged ShinyHunters exfiltration around April 18, 2026.