Carnival Corporation has confirmed a major data breach affecting nearly 6 million people after threat actors gained access to part of its IT systems through a social engineering attack.
The company, known as the world’s largest cruise line operator, said it began notifying 5,995,277 affected customers after discovering that personal information had been copied during the incident. Carnival said its security team first detected unauthorized activity involving an employee account on April 14, 2026.
According to the company’s breach notification letter, an unauthorized actor tricked an employee through social engineering and used that access to enter a limited part of Carnival’s IT system. Carnival said it quickly blocked the activity, brought in third-party security experts, and started a full investigation. On April 22, the company determined that personal information had been illegally copied.
Carnival has not publicly confirmed who was behind the attack. However, the ShinyHunters extortion gang claimed responsibility in April, saying it stole documents containing more than 8.7 million records with personally identifiable information, along with terabytes of internal company data.
Have I Been Pwned later reviewed the leaked data and said the exposed information included names, dates of birth, email addresses, genders, geographic locations, and loyalty program details. The data appeared to be connected to the Mariner Society loyalty program run by Holland America, one of Carnival’s cruise line brands.
Carnival operates several major cruise brands, including Carnival Cruise Line, Costa, Princess Cruises, Holland America Line, AIDA, Cunard, Seabourn, P&O Cruises, and others. The company served around 13.5 million guests in 2024 and reported more than $26 billion in revenue last year.
ShinyHunters has been linked to several large data theft campaigns over the past year, including attacks targeting Salesforce customers. The FBI recently advised victims of ShinyHunters not to pay ransom demands, warning that payment does not guarantee stolen data will be deleted or kept private.
This is not the first time Carnival has dealt with data security incidents. The company previously disclosed breaches in 2020 and 2021 that exposed personal and financial information belonging to customers, employees, and crew members.





