Breach report
Carnival notifies nearly 6 million people after April social engineering attack

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The cruise operator says an attacker tricked an employee on 14 April and took customer data. ShinyHunters had claimed and published 8.7 million records weeks earlier.
What happened
Carnival Corporation, the world's largest cruise operator, says the breach began with a social engineering attack on an employee on 14 April 2026, according to The Register. In April, the ShinyHunters extortion group claimed to have stolen Carnival data and then published it. Have I Been Pwned (HIBP) says that set held 8.7 million records with 7.5 million unique email addresses and appeared to come from Holland America Line's Mariner Society loyalty programme. At the time Carnival acknowledged only a phishing incident involving a single user account. On 27 May it began notifying customers and filed a notice with the Maine Attorney General.
Confirmed vs. claimed
Confirmed by Carnival: just under 6 million people are affected. Data varies by person and includes names, addresses, email addresses, phone numbers, dates of birth and state or government identification numbers. Carnival is offering 24 months of credit monitoring through TransUnion.
Claimed: ShinyHunters says it took terabytes of data and that talks with Carnival broke down. Carnival has not named the group or commented on the scale beyond its filing.
Who is affected
Carnival customers, including Holland America loyalty members. Carnival's filing does not break down affected people by country, so passengers from outside the US, including India, should not assume they are excluded.
What to do
- If you get Carnival's email, enrol in the credit monitoring it offers.
- Check your address on Have I Been Pwned.
- Expect fake booking, refund or loyalty-reward messages that quote your cruise details; log in only through the cruise line's official site.
- Change the password on your cruise account and any account where you reused it.
- See our guides on ShinyHunters extortion emails and what to do after a data breach notice.
Sources
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026