Carnival Corporation experienced a data breach where unauthorized activity was confirmed on April 22, 2026, stemming from an incident detected on April 14, 2026. The company began sending notifications to affected individuals on May 27, 2026, through "Notice of Cybersecurity Event" letters and a substitute notice PDF on their website. The breach was a result of social engineering that tricked a Carnival employee into granting access to part of their IT systems.
This incident affected 5,995,277 individuals. The exposed data types include full names, addresses, email addresses, phone numbers, dates of birth, and government-issued identification numbers. It also involved Mariner Society membership status, tier, and internal customer identifiers. While past breaches have involved SSN or medical data, their confirmation for this 2026 incident is not publicly available.
Details can emerge as investigations proceed, and notification processes may be ongoing. Carnival is offering two years of complimentary credit monitoring through TransUnion for US customers.